Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-22030 | In Mbed TLS 3.6.1 through 3.6.3 before 3.6.4, a timing discrepancy in block cipher padding removal allows an attacker to recover the plaintext when PKCS#7 padding mode is used. |
Thu, 07 Aug 2025 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Arm
Arm mbed Tls |
|
| CPEs | cpe:2.3:a:arm:mbed_tls:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Arm
Arm mbed Tls |
Mon, 21 Jul 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 20 Jul 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Mbed TLS 3.6.1 through 3.6.3 before 3.6.4, a timing discrepancy in block cipher padding removal allows an attacker to recover the plaintext when PKCS#7 padding mode is used. | |
| Weaknesses | CWE-385 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-07-21T20:37:09.142Z
Reserved: 2025-05-30T00:00:00.000Z
Link: CVE-2025-49087
Updated: 2025-07-21T20:35:46.885Z
Status : Analyzed
Published: 2025-07-20T19:15:24.037
Modified: 2025-08-07T01:21:40.363
Link: CVE-2025-49087
No data.
OpenCVE Enrichment
Updated: 2025-07-21T15:17:00Z
EUVD