CVE-2024-23170: Arm Mbed TLS

Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.

An issue was discovered in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2. There was a timing side channel in RSA private operations. This side channel could be sufficient for a local attacker to recover the plaintext. It requires the attacker to send a large number of messages for decryption, as described in "Everlasting ROBOT: the Marvin Attack" by Hubert Kario.

Affected products

  • Arm Mbed TLS: from 2.0.0, before 2.28.7 (fixed in 2.28.7)
  • Trustedfirmware Mbed TLS: from 3.0.0, before 3.5.2 (fixed in 3.5.2)

Published 2024-01-31. Last modified 2026-06-17.