We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-49087



Description

In Mbed TLS 3.6.1 through 3.6.3 before 3.6.4, a timing discrepancy in block cipher padding removal allows an attacker to recover the plaintext when PKCS#7 padding mode is used.

Reserved 2025-05-30 | Published 2025-07-20 | Updated 2025-07-20 | Assigner mitre


MEDIUM: 4.0CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N

Problem types

CWE-385 Covert Timing Channel

Product status

Default status
unaffected

3.6.1 before 3.6.4
affected

References

mbed-tls.readthedocs.io/...tech-updates/security-advisories/

github.com/...isories/mbedtls-security-advisory-2025-06-5.md

cve.org (CVE-2025-49087)

nvd.nist.gov (CVE-2025-49087)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-49087

Support options

Helpdesk Chat, Email, Knowledgebase