AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2019-18222

MEDIUM · CVSS 4.7 EPSS 0.34%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2020-01-23 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2019-18222
Severity
MEDIUM
CVSS
4.7
EPSS
0.34%

Original NVD Description

The ECDSA signature implementation in ecdsa.c in Arm Mbed Crypto 2.1 and Mbed TLS through 2.19.1 does not reduce the blinded scalar before computing the inverse, which allows a local attacker to recover the private key via side-channel attacks.