ARM Mbed TLS up to 2.16.6/2.22.x ECC Private Key information exposure

A vulnerability has been found in ARM Mbed TLS up to 2.16.6/2.22.x and classified as problematic. This vulnerability affects the function mbedtls_ecp_check_pub_priv/mbedtls_pk_parse_key/mbedtls_pk_parse_keyfile/mbedtls_ecp_mul/mbedtls_ecp_mul_restartable of the component ECC Private Key Handler. Upgrading to version 2.16.7 or 2.23.0 eliminates this vulnerability. The upgrade is hosted for download at github.com.

Common Vulnerabilityies and Exposures

Contact us to get started

CVE-2023-1501 : ROCKOA 2.3.2 ACLOUDCOSACTION.PHP.SQL RUNACTION FILEID UNRESTRICTED UPLOAD

CVE-2023-1501 : ROCKOA 2.3.2 ACLOUDCOSACTION.PHP.SQL RUNACTION FILEID UNRESTRICTED UPLOAD

Description A vulnerability, which was classified as critical, was found in RockOA 2.3.2. This affects the function runAction of the

CVE-2023-28116 : CONTIKI-NG UP TO 4.8/4.9 BLE L2CAP MODULE PACKETBUF_SIZE BUFFER OVERFLOW

CVE-2023-28116 : CONTIKI-NG UP TO 4.8/4.9 BLE L2CAP MODULE PACKETBUF_SIZE BUFFER OVERFLOW

Description Contiki-NG is an open-source, cross-platform operating system for internet of things (IoT) devices. In versions 4.8 and prior, an

CVE-2023-1256 : AVEVA PLANT SCADA/TELEMETRY SERVER IMPROPER AUTHORIZATION

CVE-2023-1256 : AVEVA PLANT SCADA/TELEMETRY SERVER IMPROPER AUTHORIZATION

Description The listed versions of AVEVA Plant SCADA and AVEVA Telemetry Server are vulnerable to an improper authorization exploit which