Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-23744


An issue was discovered in Mbed TLS 3.5.1. There is persistent handshake denial if a client sends a TLS 1.3 ClientHello without extensions.


Published

2024-01-21T23:15:44.833

Last Modified

2025-06-04T16:15:32.440

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo
  • Type: Secondary
    CWE-400

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application arm mbed_tls ≤ 3.5.1 Yes

References