Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:26142
HistoryAug 06, 2020 - 9:33 p.m.

Sensitive Information Disclosure

2020-08-0621:33:11
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
15

EPSS

0.008

Percentile

81.5%

Arm Mbed TLS is vulnerable to sensitive information leakage. When deterministic ECDSA is enabled, it uses an RNG with insufficient entropy for blinding, which might allow an attacker to recover a private key via side-channel attacks if a victim signs the same message many times.

References