PT-2023-5882 · Mbed Tls+3 · Mbed Tls+3

CVE-2023-43615

·

Publicado

2023-10-05

·

Atualizado

2025-08-21

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Mbed TLS versions 2.x before 2.28.5 Mbed TLS versions 3.x before 3.5.0
Description The issue is related to errors in handling encryption in (D)TLS connections, specifically when using zero encryption or RC4 cipher. This can allow a remote attacker to execute arbitrary code. The issue is a buffer overflow.
Recommendations For Mbed TLS versions 2.x before 2.28.5, update to version 2.28.5 or later. For Mbed TLS versions 3.x before 3.5.0, update to version 3.5.0 or later.

Exploit

Correção

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2024-15509
ALT-PU-2025-10462
BDU:2023-06575
CVE-2023-43615

Produtos afetados

Alt Linux
Debian
Mbed Tls
Red Os