CVE-2023-45199: Buffer Overflow
Published Oct 7, 2023
·Updated
Mbed TLS 3.2.x through 3.4.x before 3.5 has a Buffer Overflow that can lead to remote Code execution.
Affected Software
2 affected components
Arm mbed TLS>=3.2.0<3.5.0
TrustedFirmware Mbed Tls>=3.2.0<3.5.0
Event History
Oct 7, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-45199?
CVE-2023-45199 is a vulnerability in the Mbed TLS library that can lead to remote code execution due to a buffer overflow.
2
How severe is CVE-2023-45199?
CVE-2023-45199 has a severity rating of 9.8 (Critical).
3
Which software versions are affected by CVE-2023-45199?
Mbed TLS versions 3.2.x through 3.4.x before 3.5.0 are affected by CVE-2023-45199.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-45199?
CVE-2023-45199 is associated with CWE-119 and CWE-120.
5
How can I fix CVE-2023-45199?
To fix CVE-2023-45199, update your Mbed TLS library to version 3.5.0 or later.