PT-2024-22563 · Mbed Tls+1 · Mbed Tls+1
Hey3E
·
Published
2024-04-02
·
Updated
2025-06-10
·
CVE-2024-28755
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Mbed TLS versions 3.5.x through 3.5.x before 3.6.0
Mbed TLS versions prior to 3.6.0
Description
An issue was discovered in Mbed TLS when an SSL context was reset with the
mbedtls ssl session reset() API, the maximum TLS version to be negotiated was not restored to the configured one. An attacker was able to prevent an Mbed TLS server from establishing any TLS 1.3 connection, potentially resulting in a Denial of Service or forced version downgrade from TLS 1.3 to TLS 1.2.Recommendations
For Mbed TLS versions prior to 3.6.0, update to version 3.6.0 or later to resolve the issue.
As a temporary workaround, consider avoiding the use of the
mbedtls ssl session reset() API until a patch is available.Fix
DoS
Inadequate Encryption Strength
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Mbed Tls