ARM
ARM Mbed TLS: vulnerabilidades y CVE
ARM Mbed TLS tiene 51 vulnerabilidades publicadas, 7 de ellas en los últimos 12 meses. 9 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE51
Últimos 12 meses7
Críticas9
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-34877 | Crítica (9.8) | 0.73% | — | 2 abr 2026 | An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0. Insufficient protection of serialized SSL context or session structures allows an attacker who can modify the serialized structures… |
| CVE-2026-34872 | Crítica (9.1) | 0.28% | — | 1 abr 2026 | An issue was discovered in Mbed TLS 3.5.x and 3.6.x through 3.6.5 and TF-PSA-Crypto 1.0. There is a lack of contributory behavior in FFDH due to improper input validation. Using finite-field Diffie-Hellman, the other… |
| CVE-2025-66442 | Media (5.1) | 0.27% | — | 1 abr 2026 | In Mbed TLS through 4.0.0, there is a compiler-induced timing side channel (in RSA and CBC/ECB decryption) that only occurs with LLVM's select-optimize feature. TF-PSA-Crypto through 1.0.0 is also affected. |
| CVE-2026-34871 | Media (6.7) | 0.15% | — | 1 abr 2026 | An issue was discovered in Mbed TLS before 3.6.6 and 4.x before 4.1.0 and TF-PSA-Crypto before 1.1.0. There is a Predictable Seed in a Pseudo-Random Number Generator (PRNG). |
| CVE-2026-25835 | Alta (7.7) | 0.18% | — | 1 abr 2026 | Mbed TLS before 3.6.6 and TF-PSA-Crypto before 1.1.0 misuse seeds in a Pseudo-Random Number Generator (PRNG). |
| CVE-2025-59438 | Media (5.3) | 0.26% | — | 21 oct 2025 | Mbed TLS through 3.6.4 has an Observable Timing Discrepancy. |
| CVE-2025-54764 | Media (6.2) | 0.22% | — | 20 oct 2025 | Mbed TLS before 3.6.5 allows a local timing attack against certain RSA operations, and direct calls to mbedtls_mpi_mod_inv or mbedtls_mpi_gcd. |
| CVE-2025-47917 | Crítica (9.8) | 2.1% | — | 20 jul 2025 | Mbed TLS before 3.6.4 allows a use-after-free in certain situations of applications that are developed in accordance with the documentation. The function mbedtls_x509_string_to_names() takes a head argument that is… |
| CVE-2025-48965 | Alta (7.5) | 0.50% | — | 20 jul 2025 | Mbed TLS before 3.6.4 has a NULL pointer dereference because mbedtls_asn1_store_named_data can trigger conflicting data with val.p of NULL but val.len greater than zero. |
| CVE-2025-52497 | Media (4.8) | 0.31% | — | 4 jul 2025 | Mbed TLS before 3.6.4 has a PEM parsing one-byte heap-based buffer underflow, in mbedtls_pem_read_buffer and two mbedtls_pk_parse functions, via untrusted PEM input. |
| CVE-2025-52496 | Alta (7.8) | 0.20% | — | 4 jul 2025 | Mbed TLS before 3.6.4 has a race condition in AESNI detection if certain compiler optimizations occur. An attacker may be able to extract an AES key from a multithreaded program, or perform a GCM forgery. |
| CVE-2025-27810 | Media (4.8) | 0.29% | — | 25 mar 2025 | Mbed TLS before 2.28.10 and 3.x before 3.6.3, in some cases of failed memory allocation or hardware errors, uses uninitialized stack memory to compose the TLS Finished message, potentially leading to authentication… |
| CVE-2025-27809 | Media (5.4) | 0.20% | — | 25 mar 2025 | Mbed TLS before 2.28.10 and 3.x before 3.6.3, on the client side, accepts servers that have trusted certificates for arbitrary hostnames unless the TLS client application calls mbedtls_ssl_set_hostname. |
| CVE-2024-28960 | Alta (8.2) | 0.85% | — | 29 mar 2024 | An issue was discovered in Mbed TLS 2.18.0 through 2.28.x before 2.28.8 and 3.x before 3.6.0, and Mbed Crypto. The PSA Crypto API mishandles shared memory. |
| CVE-2024-23775 | Alta (7.5) | 1.1% | — | 31 ene 2024 | Integer Overflow vulnerability in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2, allows attackers to cause a denial of service (DoS) via mbedtls_x509_set_extension(). |
| CVE-2024-23170 | Media (5.5) | 0.31% | — | 31 ene 2024 | An issue was discovered in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2. There was a timing side channel in RSA private operations. This side channel could be sufficient for a local attacker to recover the plaintext.… |
| CVE-2023-52353 | Alta (7.5) | 0.46% | — | 21 ene 2024 | An issue was discovered in Mbed TLS through 3.5.1. In mbedtls_ssl_session_reset, the maximum negotiable TLS version is mishandled. For example, if the last connection negotiated TLS 1.2, then 1.2 becomes the new maximum. |
| CVE-2023-43615 | Alta (7.5) | 0.79% | — | 7 oct 2023 | Mbed TLS 2.x before 2.28.5 and 3.x before 3.5.0 has a Buffer Overflow. |
| CVE-2021-36647 | Media (4.7) | 0.16% | — | 17 ene 2023 | Use of a Broken or Risky Cryptographic Algorithm in the function mbedtls_mpi_exp_mod() in lignum.c in Mbed TLS Mbed TLS all versions before 3.0.0, 2.27.0 or 2.16.11 allows attackers with access to precise enough timing… |
| CVE-2022-46393 | Crítica (9.8) | 1.2% | — | 15 dic 2022 | An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. There is a potential heap-based buffer overflow and heap-based buffer over-read in DTLS if MBEDTLS_SSL_DTLS_CONNECTION_ID is enabled and… |
| CVE-2022-46392 | Media (5.3) | 0.82% | — | 15 dic 2022 | An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. An adversary with access to precise enough information about memory accesses (typically, an untrusted operating system attacking a secure enclave)… |
| CVE-2022-35409 | Crítica (9.1) | 2.3% | — | 15 jul 2022 | An issue was discovered in Mbed TLS before 2.28.1 and 3.x before 3.2.0. In some configurations, an unauthenticated attacker can send an invalid ClientHello message to a DTLS server that causes a heap-based buffer… |
| CVE-2021-43666 | Alta (7.5) | 2.1% | — | 24 mar 2022 | A Denial of Service vulnerability exists in mbed TLS 3.0.0 and earlier in the mbedtls_pkcs12_derivation function when an input password's length is 0. |
| CVE-2021-45451 | Alta (7.5) | 0.92% | — | 21 dic 2021 | In Mbed TLS before 3.1.0, psa_aead_generate_nonce allows policy bypass or oracle-based decryption when the output buffer is at memory locations accessible to an untrusted application. |
| CVE-2021-44732 | Crítica (9.8) | 2.6% | — | 20 dic 2021 | Mbed TLS before 3.0.1 has a double free in certain out-of-memory conditions, as demonstrated by an mbedtls_ssl_set_session() failure. |
| CVE-2020-36478 | Alta (7.5) | 1.1% | — | 23 ago 2021 | An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). A NULL algorithm parameters entry looks identical to an array of REAL (size zero) and thus the certificate is considered… |
| CVE-2020-36477 | Media (5.9) | 0.86% | — | 23 ago 2021 | An issue was discovered in Mbed TLS before 2.24.0. The verification of X.509 certificates when matching the expected common name (the cn argument of mbedtls_x509_crt_verify) with the actual certificate name is… |
| CVE-2020-36476 | Alta (7.5) | 1.6% | — | 23 ago 2021 | An issue was discovered in Mbed TLS before 2.24.0 (and before 2.16.8 LTS and before 2.7.17 LTS). There is missing zeroization of plaintext buffers in mbedtls_ssl_read to erase unused application data from memory. |
| CVE-2020-36475 | Alta (7.5) | 1.9% | — | 23 ago 2021 | An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). The calculations performed by mbedtls_mpi_exp_mod are not limited; thus, supplying overly large parameters could lead to… |
| CVE-2020-36426 | Alta (7.5) | 1.7% | — | 19 jul 2021 | An issue was discovered in Arm Mbed TLS before 2.24.0. mbedtls_x509_crl_parse_der has a buffer over-read (of one byte). |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.