Cryptographic issues in mbed TLS - CVE-2023-52353
Published: August 7, 2025
Vulnerability identifier: #VU113735
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-52353
CWE-ID: CWE-310
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to downgrade TLS connection.
The issue exists due to the application does not have version negotiations process implemented when using TLS 1.3. An attacker can downgrade TLS 1.3 to previously used protocol potentially allowing MitM attacks.
Affected software
mbed TLS
How to mitigate CVE-2023-52353
Install updates from vendor's website.
mbed TLS - update to 3.6.1