7.5
CVSSv3

CVE-2023-52353

Published: 21/01/2024 Updated: 29/01/2024
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

An issue exists in Mbed TLS up to and including 3.5.1. In mbedtls_ssl_session_reset, the maximum negotiable TLS version is mishandled. For example, if the last connection negotiated TLS 1.2, then 1.2 becomes the new maximum.

Vulnerable Product Search on Vulmon Subscribe to Product

arm mbed tls