Mbed TLS
cpe:2.3:a:arm:mbed_tls:*:*:*:*:*:*:*, +1 more
- < 3.6.4
A race condition vulnerability has been identified in Mbed TLS versions prior to 3.6.4, specifically in the AESNI detection process. This vulnerability arises when certain compiler optimizations are applied. In a multithreaded environment, an attacker may exploit this race condition to extract an AES key from the program or to forge GCM (Galois/Counter Mode) authentication.
Exploitation of this vulnerability could lead to the extraction of AES keys from a multithreaded program or allow for GCM forgery, undermining the integrity of GCM authentication.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.