Logo
vulnerabilityCVE-2024-45157
Name
CVE-2024-45157
Source
NVD ( link)Debian ( link)
Description
An issue was discovered in Mbed TLS before 2.28.9 and 3.x before 3.6.1, in which the user-selected algorithm is not used. Unlike previously documented, enabling MBEDTLS_PSA_HMAC_DRBG_MD_TYPE does not cause the PSA subsystem to use HMAC_DRBG: it uses HMAC_DRBG only when MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG and MBEDTLS_CTR_DRBG_C are disabled.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis

Vulnerability Ratings#


5.1
CVSSv31
5.1
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
3.6.6
Not Affected
buildroot
master
3.6.6
Not Affected
openwrt
master
3.6.7-r1
Not Affected
openwrt
openwrt-25.12
3.6.7-r1
Not Affected
yocto
master
3.6.7
Not Affected
yocto
scarthgap
2.28.10
Not Affected