CVE-2020-36475
—CVSS 3.1
7.5 high
EPSS
2%p79
Published
()
Modified
Description
An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). The calculations performed by mbedtls_mpi_exp_mod are not limited; thus, supplying overly large parameters could lead to denial of service when generating Diffie-Hellman key pairs.
In the news0 stories
No ingested article mentions this CVE yet.