Mbed TLS
cpe:2.3:a:arm:mbed_tls:*:*:*:*:*:*:*, +1 more
- >= 3.6.1, < 3.6.4
A timing side-channel vulnerability has been identified in Mbed TLS versions 3.6.1 through 3.6.3 prior to 3.6.4. This vulnerability arises during the removal of padding in block cipher decryption when PKCS#7 padding mode is used, allowing an attacker to recover the plaintext.
Exploitation of this vulnerability could lead to unauthorized plaintext recovery by exploiting the timing discrepancy in padding removal.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.