CVE-2022-46392
Last modified
CVE-2022-46392 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. An adversary with access to precise enough information about memory accesses (typically, an untrusted operating system attacking a secure enclave) can recover an RSA private key after observing the victim performing a single private-key operation, if the window size (MBEDTLS_MPI_WINDOW_SIZE) used for the exponentiation is 3 or smaller.. EPSS estimates a 0.79% chance of exploitation in the next 30 days.
Description
An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. An adversary with access to precise enough information about memory accesses (typically, an untrusted operating system attacking a secure enclave) can recover an RSA private key after observing the victim performing a single private-key operation, if the window size (MBEDTLS_MPI_WINDOW_SIZE) used for the exponentiation is 3 or smaller.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Arm | Mbed Tls | < 2.28.2 |
| Trustedfirmware | Mbed Tls | >= 3.0.0, < 3.3.0 |
| Fedoraproject | Fedora | 36 |
| Fedoraproject | Fedora | 37 |
References
- https://github.com/Mbed-TLS/mbedtls/releases/tag/v2.28.2Release Notes, Third Party Advisory
- https://github.com/Mbed-TLS/mbedtls/releases/tag/v3.3.0Release Notes, Third Party Advisory
- https://github.com/Mbed-TLS/mbedtls/releases/tag/v2.28.2Release Notes, Third Party Advisory
- https://github.com/Mbed-TLS/mbedtls/releases/tag/v3.3.0Release Notes, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-46392?
How severe is CVE-2022-46392?
How do I fix CVE-2022-46392?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-46382RackN Digital Rebar through 4.6.14, 4.7 through 4.7.22, 4.8 …8.8
- CVE-2022-46383RackN Digital Rebar through 4.6.14, 4.7 through 4.7.22, 4.8 …9.8
- CVE-2022-46387ConEmu through 220807 and Cmder before 1.3.21 report the tit…9.8
- CVE-2022-46389There exists a reflected XSS within the logout functionality…6.1
- CVE-2022-4639A vulnerability, which was classified as critical, has been …9.8
- CVE-2022-46391AWStats 7.x through 7.8 allows XSS in the hostinfo plugin du…6.1
- CVE-2022-46393An issue was discovered in Mbed TLS before 2.28.2 and 3.x be…9.8
- CVE-2022-46394An issue was discovered in the Arm Mali GPU Kernel Driver. A…8.8
- CVE-2022-46395An issue was discovered in the Arm Mali GPU Kernel Driver. A…8.8
- CVE-2022-46396An issue was discovered in the Arm Mali Kernel Driver. A non…3.3
- CVE-2022-46397FP.io VPP (Vector Packet Processor) 22.10, 22.06, 22.02, 21.…7.5
- CVE-2022-46399The Microchip RN4870 module firmware 1.43 (and the Microchip…7.5
Are you affected by CVE-2022-46392?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
