Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-71451
HistoryAug 24, 2021 - 12:00 a.m.

ARM mbed TLS denial of service vulnerability

2021-08-2400:00:00
China National Vulnerability Database
www.cnvd.org.cn
13
arm uk
secure communication
encryption
denial of service
vulnerability
mbedtls_mpi_exp_mod
diffie-hellman

EPSS

0.008

Percentile

81.5%

ARM mbed TLS is a product from ARM UK that provides secure communication and encryption for mbed products. ARM mbed TLS suffers from a denial of service vulnerability that stems from an unrestricted calculation performed by mbedtls_mpi_exp_mod. An attacker could exploit this vulnerability to provide overly large parameters potentially resulting in a denial of service when generating Diffie-Hellman key pairs.