Back to Database
Status published
High
CVE-2021-45451
In Mbed TLS before 3.1.0, psa_aead_generate_nonce allows policy bypass or...
Vulnerability Description
In Mbed TLS before 3.1.0, psa_aead_generate_nonce allows policy bypass or oracle-based decryption when the output buffer is at memory locations accessible to an untrusted application.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-45451
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/ARMmbed/mbedtls/releases/tag/v3.1.0
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TALJHOYAYSUJTLN6BYGLO4YJGNZUY74W/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IL66WKJGXY5AXMTFE7QDMGL3RIBD6PX5/
More from arm
View All →CVE-2022-48251
The AES instructions on the ARMv8 platform do not have...
High
7.5
CVE-2022-46891
An issue was discovered in the Arm Mali GPU Kernel...
High
8.8
CVE-2022-46781
An issue was discovered in the Arm Mali GPU Kernel...
Unknown
0
CVE-2022-46396
An issue was discovered in the Arm Mali Kernel Driver....
Unknown
0
CVE-2022-46395
An issue was discovered in the Arm Mali GPU Kernel...
High
8.8
Affected Vendor
Affected Software
mbed tls, fedora
Vulnerable Versions:
0, 36, 37
Timeline
Official Publish:
December 21st, 2021
Last Modified:
August 4th, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.