CVE-2025-49087

In Mbed TLS 3.6.1 through 3.6.3 before 3.6.4, a timing discrepancy in block cipher padding removal allows an attacker to recover the plaintext when PKCS#7 padding mode is used.
Configurations

No configuration.

History

22 Jul 2025, 13:06

Type Values Removed Values Added
Summary
  • (es) En Mbed TLS 3.6.1 a 3.6.3 antes de 3.6.4, una discrepancia de tiempo en la eliminación del relleno del cifrado de bloque permite que un atacante recupere el texto sin formato cuando se utiliza el modo de relleno PKCS#7.

20 Jul 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-20 19:15

Updated : 2025-07-22 13:06


NVD link : CVE-2025-49087

Mitre link : CVE-2025-49087

CVE.ORG link : CVE-2025-49087


JSON object : View

Products Affected

No product.

CWE
CWE-385

Covert Timing Channel