Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-34873

Опубликовано: 01 апр. 2026
Источник: redhat
CVSS3: 10
EPSS Низкий

Описание

An issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impersonation can occur while resuming a TLS 1.3 session.

A flaw was found in Mbed TLS. This vulnerability allows a remote attacker to impersonate a client during the resumption of a TLS 1.3 session. This could lead to unauthorized access or other security breaches by allowing the attacker to act as a legitimate client.

Отчет

This Critical flaw in Mbed TLS allows a remote attacker to impersonate a client during TLS 1.3 session resumption, potentially leading to unauthorized access. Red Hat products utilizing Mbed TLS for client-side TLS 1.3 session resumption are affected if this feature is enabled.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Дополнительная информация

Статус:

Critical
Дефект:
CWE-290
https://bugzilla.redhat.com/show_bug.cgi?id=2454108mbedtls: Mbed TLS: Client impersonation during TLS 1.3 session resumption

EPSS

Процентиль: 15%
0.00241
Низкий

10 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.1
ubuntu
4 месяца назад

An issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impersonation can occur while resuming a TLS 1.3 session.

CVSS3: 9.1
nvd
4 месяца назад

An issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impersonation can occur while resuming a TLS 1.3 session.

msrc
3 месяца назад

An issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impersonation can occur while resuming a TLS 1.3 session.

CVSS3: 9.1
debian
4 месяца назад

An issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impers ...

CVSS3: 9.1
github
4 месяца назад

An issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impersonation can occur while resuming a TLS 1.3 session.

EPSS

Процентиль: 15%
0.00241
Низкий

10 Critical

CVSS3