Medium severity5.5NVD Advisory· Published Jan 31, 2024· Updated Jun 17, 2026
CVE-2024-23170
CVE-2024-23170
Description
An issue was discovered in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2. There was a timing side channel in RSA private operations. This side channel could be sufficient for a local attacker to recover the plaintext. It requires the attacker to send a large number of messages for decryption, as described in "Everlasting ROBOT: the Marvin Attack" by Hubert Kario.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8- Mbed TLS/Mbed TLSdescription
- osv-coords4 versionspkg:rpm/opensuse/mbedtls-2&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/mbedtls&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/mbedtls&distro=openSUSE%20Tumbleweedpkg:rpm/suse/mbedtls&distro=SUSE%20Package%20Hub%2015%20SP5
< 2.28.7-1.1+ 3 more
- (no CPE)range: < 2.28.7-1.1
- (no CPE)range: < 2.28.7-bp155.2.3.1
- (no CPE)range: < 3.5.2-1.1
- (no CPE)range: < 2.28.7-bp155.2.3.1
Patches
Vulnerability mechanics
References
5- mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2024-01-1/nvdVendor Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GP5UU7Z6LJNBLBT4SC5WWS2HDNMTFZH5/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IIBPEYSVRK4IFLBSYJAWKH33YBNH5HR2/nvd
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GP5UU7Z6LJNBLBT4SC5WWS2HDNMTFZH5/nvd
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IIBPEYSVRK4IFLBSYJAWKH33YBNH5HR2/nvd
News mentions
0No linked articles in our index yet.