Vulnerability Description
An issue was discovered in Mbed TLS through 3.5.1. In mbedtls_ssl_session_reset, the maximum negotiable TLS version is mishandled. For example, if the last connection negotiated TLS 1.2, then 1.2 becomes the new maximum.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Arm | Mbed Tls | < 3.5.2 |
Related Weaknesses (CWE)
References
- https://github.com/Mbed-TLS/mbedtls/issues/8654ExploitIssue TrackingPatch
- https://github.com/Mbed-TLS/mbedtls/issues/8654ExploitIssue TrackingPatch
FAQ
What is CVE-2023-52353?
CVE-2023-52353 is a vulnerability with a CVSS score of 7.5 (HIGH). An issue was discovered in Mbed TLS through 3.5.1. In mbedtls_ssl_session_reset, the maximum negotiable TLS version is mishandled. For example, if the last connection negotiated TLS 1.2, then 1.2 beco...
How severe is CVE-2023-52353?
CVE-2023-52353 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-52353?
Check the references section above for vendor advisories and patch information. Affected products include: Arm Mbed Tls.