Lucene search

K
cvelistMitreCVELIST:CVE-2023-26084
HistoryMar 15, 2023 - 12:00 a.m.

CVE-2023-26084

2023-03-1500:00:00
mitre
www.cve.org
4
arm aarch64cryptolib
api
aes-gcm
authentication tag verification
man-in-the-middle attack
improperly initialized variable

AI Score

4.7

Confidence

High

EPSS

0.001

Percentile

27.1%

The armv8_dec_aes_gcm_full() API of Arm AArch64cryptolib before 86065c6 fails to the verify the authentication tag of AES-GCM protected data, leading to a man-in-the-middle attack. This occurs because of an improperly initialized variable.

AI Score

4.7

Confidence

High

EPSS

0.001

Percentile

27.1%

Related for CVELIST:CVE-2023-26084