CVEPublished 2024-09-05Modified 2026-06-050 articles on news6 live referencesNVD data

CVE-2024-45157Trustedfirmware · Mbed_tls

Vulnerability data via NVD (ingested)

CVSS v3.1
5.1
MEDIUM
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS percentile
31
Exploit Prediction Scoring System · top 69% of all CVEs
Description

An issue was discovered in Mbed TLS before 2.28.9 and 3.x before 3.6.1, in which the user-selected algorithm is not used. Unlike previously documented, enabling MBEDTLS_PSA_HMAC_DRBG_MD_TYPE does not cause the PSA subsystem to use HMAC_DRBG: it uses HMAC_DRBG only when MBEDTLS_PSA_CRYPTO_EXTERNAL_RNG and MBEDTLS_CTR_DRBG_C are disabled.

Timeline
Published 2024-09-05
Modified 2026-06-05

External references

Search for exposed instances

Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).

More intel sources (5)

Known PoCs on GitHub (2)

We haven't classified any articles referencing CVE-2024-45157 yet. The external references above still apply.