← Back to CVE List

CVE-2022-46392

Published: 2022-12-15T23:15Z
Last Modified: 2024-11-21T07:30Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. An adversary with access to precise enough information about memory accesses (typically, an untrusted operating system attacking a secure enclave) can recover an RSA private key after observing the victim performing a single private-key operation, if the window size (MBEDTLS_MPI_WINDOW_SIZE) used for the exponentiation is 3 or smaller. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt