Cryptographic issues in mbed TLS - CVE-2023-52353

 

Cryptographic issues in mbed TLS - CVE-2023-52353

Published: August 7, 2025


Vulnerability identifier: #VU113735
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-52353
CWE-ID: CWE-310
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to downgrade TLS connection.

The issue exists due to the application does not have version negotiations process implemented when using TLS 1.3. An attacker can downgrade TLS 1.3 to previously used protocol potentially allowing MitM attacks. 


Affected software

mbed TLS

How to mitigate CVE-2023-52353

Install updates from vendor's website.

mbed TLS - update to 3.6.1

External References

Related Security Bulletins