An issue was discovered in Mbed TLS through 3.5.1. In mbedtls_ssl_session_reset, the maximum negotiable TLS version is mishandled. For example, if the last connection negotiated TLS 1.2, then 1.2 becomes the new maximum.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://github.com/Mbed-TLS/mbedtls/issues/8654 |
|
History
Fri, 30 May 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-05-30T14:23:51.020Z
Reserved: 2024-01-21T00:00:00.000Z
Link: CVE-2023-52353
Updated: 2024-08-02T22:55:41.778Z
Status : Modified
Published: 2024-01-21T23:15:44.220
Modified: 2025-05-30T15:15:27.850
Link: CVE-2023-52353
No data.
OpenCVE Enrichment
No data.
Weaknesses