CVE-2024-45157
MEDIUMDescription
An issue was discovered in Mbed TLS before 2.28.9 and 3.x before 3.6.1, in which the user-selected algorithm is not used. Unlike previously documented, enabling MBEDTLS_PSA_HMAC_DRBG_MD_TYPE does not cause the PSA subsystem to use HMAC_DRBG: it uses HMAC_DRBG only when MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG and MBEDTLS_CTR_DRBG_C are disabled.
Is your site exposed to CVE-2024-45157?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| arm | mbed_tls |
| arm | mbed_tls |
References
Frequently Asked Questions
What is CVE-2024-45157? +
How severe is CVE-2024-45157? +
What products are affected by CVE-2024-45157? +
How do I check if I'm vulnerable to CVE-2024-45157? +
Related Vulnerabilities
GitHub Copilot CLI brings AI-powered coding assistance directly to your command line. Prior to 1.0.43, a security vulnerability has been …
Due to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematurely during system shutdown. …
UltraDAG is a minimal DAG-BFT blockchain in Rust. In version 0.1, a non-council attacker can submit a signed SmartOp::Vote transaction …
Due to incorrect behavior order a low privileged remote attacker could trigger account inconsistent state via crafted input and overwrites …
API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. Prior to 4.0.22 and 3.4.17, a GraphQL …
Incorrect behavior order in transition between executive monitor and SMI transfer monitor (STM) in some Intel(R) Processor may allow a …