« List of all CVEs

CVE-2022-46392

Published: 12/15/2022 Last updated: 4/21/2025 Reserved: 12/4/2022

An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. An adversary with access to precise enough information about memory accesses (typically, an untrusted operating system attacking a secure enclave) can recover an RSA private key after observing the victim performing a single private-key operation, if the window size (MBEDTLS_MPI_WINDOW_SIZE) used for the exponentiation is 3 or smaller.

CNA assigner: mitre (8254265b-2729-46b6-b9e3-3dfca2d5bfca) Requested by: n/a

Metrics

Version Score Severity Vector String
3.1 5.3 Medium CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N

Opam packages affected (1)

conf-mbedtls

Products affected (1)

Product Vendor Version
n/a n/a < 6422e8471890273994fe8cc6d452b0dcd2c9483e

References (8)