Mbed TLS 3.5.x through 3.6.x before 3.6.2 has a buffer underrun in pkwrite when writing an opaque key pair
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 11 Jul 2025 22:45:00 +0900

Type Values Removed Values Added
Metrics epss

{'score': 0.00308}

epss

{'score': 0.00342}


Wed, 07 May 2025 03:30:00 +0900

Type Values Removed Values Added
First Time appeared Arm
Arm mbed Tls
CPEs cpe:2.3:a:arm:mbed_tls:*:*:*:*:*:*:*:*
Vendors & Products Arm
Arm mbed Tls

Tue, 26 Nov 2024 06:15:00 +0900

Type Values Removed Values Added
First Time appeared Mbed
Mbed mbedtls
CPEs cpe:2.3:a:mbed-tls:mbedtls:*:*:*:*:*:*:*:* cpe:2.3:a:mbed:mbedtls:*:*:*:*:*:*:*:*
Vendors & Products Mbed-tls
Mbed-tls mbedtls
Mbed
Mbed mbedtls

Fri, 18 Oct 2024 03:15:00 +0900

Type Values Removed Values Added
First Time appeared Mbed-tls
Mbed-tls mbedtls
Weaknesses CWE-787
CPEs cpe:2.3:a:mbed-tls:mbedtls:*:*:*:*:*:*:*:*
Vendors & Products Mbed-tls
Mbed-tls mbedtls
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Oct 2024 04:45:00 +0900

Type Values Removed Values Added
Description Mbed TLS 3.5.x through 3.6.x before 3.6.2 has a buffer underrun in pkwrite when writing an opaque key pair
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-11-25T20:53:41.370Z

Reserved: 2024-10-13T00:00:00

Link: CVE-2024-49195

cve-icon Vulnrichment

Updated: 2024-10-17T17:23:41.588Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-15T20:15:21.950

Modified: 2025-05-06T18:01:24.893

Link: CVE-2024-49195

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses