CVE-2024-45159: Critical severity TrustedFirmware Mbed Tls vulnerability

Published Sep 5, 2024
·
Updated

An issue was discovered in Mbed TLS 3.x before 3.6.1. With TLS 1.3, when a server enables optional authentication of the client, if the client-provided certificate does not have appropriate values in if keyUsage or extKeyUsage extensions, then the return value of mbedtlssslgetverifyresult() would incorrectly have the MBEDTLSX509BADCERTKEYUSAGE and MBEDTLSX509BADCERTKEYUSAGE bits clear. As a result, an attacker that had a certificate valid for uses other than TLS client authentication would nonetheless be able to use it for TLS client authentication. Only TLS 1.3 servers were affected, and only with optional authentication (with required authentication, the handshake would be aborted with a fatal alert).

Affected Software

1 affected component
TrustedFirmware Mbed Tls>=3.2.0<3.6.1

Event History

Sep 5, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-45159?

CVE-2024-45159 is considered a medium severity vulnerability due to its potential impact on the verification of client certificates in TLS 1.3.

2

How do I fix CVE-2024-45159?

To address CVE-2024-45159, upgrade to Mbed TLS version 3.6.1 or later.

3

What software is affected by CVE-2024-45159?

CVE-2024-45159 affects Mbed TLS versions 3.2.0 through 3.6.0.

4

What are the consequences of not addressing CVE-2024-45159?

Failing to address CVE-2024-45159 may result in improper certificate verification, potentially allowing unauthorized access.

5

Is there a workaround for CVE-2024-45159?

Currently, the recommended solution for CVE-2024-45159 is to update to a secure version, as no reliable workaround is available.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203