Vulnerabilities > CVE-2021-24119 - Information Exposure Through Discrepancy vulnerability in multiple products

047910
CVSS 4.9 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
HIGH
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
arm
fedoraproject
debian
CWE-203

Summary

In Trusted Firmware Mbed TLS 2.24.0, a side-channel vulnerability in base64 PEM file decoding allows system-level (administrator) attackers to obtain information about secret RSA keys via a controlled-channel and side-channel attack on software running in isolated environments that can be single stepped, especially Intel SGX.

Vulnerable Configurations

Part Description Count
Application
Arm
146
OS
Fedoraproject
2
OS
Debian
2

Common Weakness Enumeration (CWE)