CVE-2018-19608: Arm Mbed TLS
Medium severity, CVSS 4.7. EPSS: 0.3% chance of exploitation in the next 30 days.
Arm Mbed TLS before 2.14.1, before 2.7.8, and before 2.1.17 allows a local unprivileged attacker to recover the plaintext of RSA decryption, which is used in RSA-without-(EC)DH(E) cipher suites.
Affected products
- Arm Mbed TLS: from 2.1.0, before 2.1.17 (fixed in 2.1.17); from 2.7.0, before 2.7.8 (fixed in 2.7.8)
- Trustedfirmware Mbed TLS: from 2.14.0, before 2.14.1 (fixed in 2.14.1)
Published 2018-12-05. Last modified 2026-06-17.