CVE-2019-17023: Medium severity IBM Cognos Analytics vulnerability
A protocol downgrade flaw was found in Network Security Services (NSS). After a HelloRetryRequest has been sent, the client may negotiate a lower protocol than TLS 1.3, resulting in an invalid state transition in the TLS State Machine. If the client gets into this state, incoming Application Data records will be ignored.
Other sources
After a HelloRetryRequest has been sent, the client may negotiate a lower protocol that TLS 1.3, resulting in an invalid state transition in the TLS State Machine. If the client gets into this state, incoming Application Data records will be ignored.
Mozilla Firefox could allow a remote attacker to bypass security restrictions, caused by the negotiaition of a lower protocol after a HelloRetryRequest is sent. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to trigger an invalid state transition in the TLS State Machine to ignore incoming Application Data records.
— IBM
Affected Software
Remediation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2019-17023?
CVE-2019-17023 is a protocol downgrade vulnerability in Network Security Services (NSS) that allows for an invalid state transition in the TLS State Machine.
Which software is affected by CVE-2019-17023?
Mozilla Firefox versions up to 72 and Red Hat packages nss, nspr, nss-softokn, and nss-util versions up to 3.49, 4.25.0-2.el7_9, 3.53.1-3.el7_9, 3.53.1-6.el7_9, 3.53.1-1.el7_9, 4.25.0-2.el8_2, and 3.53.1-11.el8_2 are affected.
What is the severity of CVE-2019-17023?
CVE-2019-17023 has a severity rating of 5.3 (medium).
How can I fix CVE-2019-17023?
To fix CVE-2019-17023, update Mozilla Firefox to version 72 or later, and update the affected Red Hat packages (nss, nspr, nss-softokn, nss-util) to versions 3.49, 4.25.0-2.el7_9, 3.53.1-3.el7_9, 3.53.1-6.el7_9, 3.53.1-1.el7_9, 4.25.0-2.el8_2, or 3.53.1-11.el8_2 or later.
Where can I find more information about CVE-2019-17023?
You can find more information about CVE-2019-17023 on the Mozilla Bugzilla page at https://bugzilla.mozilla.org/show_bug.cgi?id=CVE-2019-17023.