CVE-2024-23744: High severity Microsoft cbl2 hvloader 1.0.1-5 vulnerability
Published Jan 21, 2024
·Updated
An issue was discovered in Mbed TLS 3.5.1. There is persistent handshake denial if a client sends a TLS 1.3 ClientHello without extensions.
Affected Software
2 affected componentsFixes available
TrustedFirmware Mbed Tls>3.4.0<=3.5.1
Microsoft cbl2 hvloader 1.0.1-5<1.0.1-6
1.0.1-6
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.0.1-6
Event History
Jan 21, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·11:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Nov 28, 2024
Data Sourced
via Microsoft·08:00 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:00 AM
Severity
Updated
via Microsoft·08:00 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2024-23744?
CVE-2024-23744 is considered a moderate severity vulnerability due to its potential impact on TLS handshakes.
2
How do I fix CVE-2024-23744?
To fix CVE-2024-23744, update Mbed TLS to version 3.5.1 or later.
3
What is the impact of CVE-2024-23744 on Mbed TLS?
CVE-2024-23744 causes a persistent handshake denial if a client sends a TLS 1.3 ClientHello without extensions.
4
Which versions of Mbed TLS are affected by CVE-2024-23744?
Mbed TLS versions between 3.4.0 and 3.5.1 are affected by CVE-2024-23744.
5
Is there a workaround for CVE-2024-23744?
There is no known workaround for CVE-2024-23744 other than upgrading to a secure version.