CVE Vulnerabilities

CVE-2018-19608

Improper Privilege Management

Published: Dec 05, 2018 | Modified: Nov 21, 2024
CVSS 3.x
4.7
MEDIUM
Source:
NVD
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
1.9 LOW
AV:L/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Arm Mbed TLS before 2.14.1, before 2.7.8, and before 2.1.17 allows a local unprivileged attacker to recover the plaintext of RSA decryption, which is used in RSA-without-(EC)DH(E) cipher suites.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
Mbed_tlsArm2.1.0 (including)2.1.17 (excluding)
Mbed_tlsArm2.7.0 (including)2.7.8 (excluding)
Mbed_tlsArm2.14.0 (including)2.14.1 (excluding)
MbedtlsUbuntubionic*
MbedtlsUbuntutrusty*
MbedtlsUbuntuupstream*
MbedtlsUbuntuxenial*
PolarsslUbuntutrusty*

Potential Mitigations

References