An issue was discovered in Arm Mbed TLS before 2.24.0. An attacker can recover a private key (for RSA or static Diffie-Hellman) via a side-channel attack against generation of base blinding/unblinding values.
| Product | Vendor | Version |
|---|---|---|
| n/a | n/a | >=3.6.0, <3.6.2 |
| n/a | n/a | 10.4.4 |