High severity7.5NVD Advisory· Published Mar 24, 2022· Updated Jun 17, 2026
CVE-2021-43666
CVE-2021-43666
Description
A Denial of Service vulnerability exists in mbed TLS 3.0.0 and earlier in the mbedtls_pkcs12_derivation function when an input password's length is 0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- mbed TLS/mbed TLSdescription
Patches
Vulnerability mechanics
References
3- github.com/ARMmbed/mbedtls/issues/5136nvdExploitIssue TrackingThird Party Advisory
- lists.debian.org/debian-lts-announce/2022/12/msg00036.htmlnvdMailing ListThird Party Advisory
- lists.debian.org/debian-lts-announce/2025/06/msg00034.htmlnvd
News mentions
0No linked articles in our index yet.