CVE-2022-46392
Mbed TLS vulnerability analysis and mitigation

Overview

CVE-2022-46392 affects Mbed TLS versions before 2.28.2 and 3.x before 3.3.0. The vulnerability was discovered in December 2022 and involves a side-channel attack against RSA private key operations. The affected software, Mbed TLS, is a lightweight open-source cryptographic and SSL/TLS library written in C, commonly used in embedded applications (NVD, Mbed Release).

Technical details

The vulnerability occurs when the window size (MBEDTLS_MPI_WINDOW_SIZE) used for RSA exponentiation is 3 or smaller. The issue was discovered by researchers Zili KOU, Wenjian HE, Sharad Sinha, and Wei ZHANG, and was detailed in their paper 'Cache Side-channel Attacks and Defenses of the Sliding Window Algorithm in TEEs' presented at Design, Automation and Test in Europe 2023. The vulnerability has been assigned a CVSS v3.1 Base Score of 5.3 (Medium) with vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N (NVD).

Impact

An adversary with access to precise enough information about memory accesses can recover an RSA private key after observing the victim performing a single private-key operation. This typically occurs in scenarios where an untrusted operating system is attacking a secure enclave (NVD).

Mitigation and workarounds

The vulnerability has been fixed in Mbed TLS versions 2.28.2 and 3.3.0. Users are recommended to upgrade to these or later versions. Fedora has released security updates for both Fedora 36 and 37 to address this vulnerability (Fedora 36, Fedora 37).

Additional resources


SourceThis report was generated using AI

Related Mbed TLS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-47917CRITICAL9.8
  • Mbed TLSMbed TLS
  • dolphin-emu-nogui-debuginfo
NoYesJul 20, 2025
CVE-2025-48965HIGH7.5
  • Mbed TLSMbed TLS
  • dolphin-emu
NoYesJul 20, 2025
CVE-2025-54764MEDIUM6.2
  • Mbed TLSMbed TLS
  • mbedtls-devel
NoYesOct 20, 2025
CVE-2025-59438MEDIUM5.3
  • Mbed TLSMbed TLS
  • micropython
NoYesOct 21, 2025
CVE-2025-49087LOW3.7
  • Mbed TLSMbed TLS
  • mbedtls
NoYesJul 20, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management