PT-2024-20052 · Mbed Tls+1 · Mbed Tls+1

Hey3Eo

·

Published

2024-01-21

·

Updated

2024-11-14

·

CVE-2024-23744

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Mbed TLS version 3.5.1
Description An issue was discovered in Mbed TLS where there is persistent handshake denial if a client sends a TLS 1.3 ClientHello without extensions.
Recommendations For Mbed TLS version 3.5.1, consider updating to a newer version that addresses this issue, as the current version may cause persistent handshake denial under specific conditions. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Resource Exhaustion

Weakness Enumeration

Related Identifiers

ALT-PU-2024-15509
ALT-PU-2024-1578
CVE-2024-23744

Affected Products

Alt Linux
Mbed Tls