CVE-2023-52353: High severity Arm mbed TLS vulnerability
An issue was discovered in Mbed TLS through 3.5.1. In mbedtlssslsessionreset the maximum negotiable TLS version is mishandled.
Other sources
An issue was discovered in Mbed TLS through 3.5.1. In mbedtlssslsessionreset, the maximum negotiable TLS version is mishandled. For example, if the last connection negotiated TLS 1.2, then 1.2 becomes the new maximum.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-52353?
The severity of CVE-2023-52353 is rated as high due to the mishandling of maximum negotiable TLS versions.
How do I fix CVE-2023-52353?
To fix CVE-2023-52353, upgrade Mbed TLS to version 3.5.2 or later.
What versions of Mbed TLS are affected by CVE-2023-52353?
Mbed TLS versions up to 3.5.1 are affected by CVE-2023-52353.
What types of applications are impacted by CVE-2023-52353?
Applications using Mbed TLS for secure communication are impacted by CVE-2023-52353.
Can CVE-2023-52353 lead to security breaches?
Yes, CVE-2023-52353 can potentially allow attackers to exploit the mishandling of TLS versions, leading to downgrade attacks.