CVE-2024-23744Uncontrolled Resource Consumption in ARM Mbed TLS

Severity
7.5HIGHNVD
EPSS
0.0%
top 84.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 21
Latest updateJan 22

Description

An issue was discovered in Mbed TLS 3.5.1. There is persistent handshake denial if a client sends a TLS 1.3 ClientHello without extensions.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages1 packages

NVDarm/mbed_tls3.5.1

Patches

🔴Vulnerability Details

3
GHSA
GHSA-627f-4vcr-fmq4: An issue was discovered in Mbed TLS 32024-01-22
OSV
CVE-2024-23744: An issue was discovered in Mbed TLS 32024-01-21
CVEList
CVE-2024-23744: An issue was discovered in Mbed TLS 32024-01-21

📋Vendor Advisories

2
Microsoft
An issue was discovered in Mbed TLS 3.5.1. There is persistent handshake denial if a client sends a TLS 1.3 ClientHello without extensions.2024-01-09
Debian
CVE-2024-23744: mbedtls - An issue was discovered in Mbed TLS 3.5.1. There is persistent handshake denial ...2024
CVE-2024-23744 — Uncontrolled Resource Consumption | cvebase