PT-2024-14545 · Mbed Tls+1 · Mbed Tls+1

Hey3Eo

·

Published

2024-01-21

·

Updated

2024-11-14

·

CVE-2023-52353

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Mbed TLS versions through 3.5.1
Description An issue was discovered in the mbedtls ssl session reset function, where the maximum negotiable TLS version is mishandled. For example, if the last connection negotiated TLS 1.2, then 1.2 becomes the new maximum.
Recommendations For Mbed TLS versions through 3.5.1, consider updating to a version that fixes the issue in the mbedtls ssl session reset function. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Session Fixation

Weakness Enumeration

Related Identifiers

ALT-PU-2024-15509
ALT-PU-2024-1578
CVE-2023-52353

Affected Products

Alt Linux
Mbed Tls