Vulnerability Name: | CVE-2019-17023 (CCN-174062) | ||||||||||||||||||||||||||||||||
Assigned: | 2019-09-30 | ||||||||||||||||||||||||||||||||
Published: | 2020-01-07 | ||||||||||||||||||||||||||||||||
Updated: | 2023-01-27 | ||||||||||||||||||||||||||||||||
Summary: | After a HelloRetryRequest has been sent, the client may negotiate a lower protocol that TLS 1.3, resulting in an invalid state transition in the TLS State Machine. If the client gets into this state, incoming Application Data records will be ignored. This vulnerability affects Firefox < 72. | ||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 6.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N) 5.7 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C)
5.7 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C)
4.6 Medium (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
| ||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2019-17023 Source: security@mozilla.org Type: Issue Tracking, Permissions Required security@mozilla.org Source: XF Type: UNKNOWN firefox-cve201917023-sec-bypass(174062) Source: security@mozilla.org Type: Third Party Advisory security@mozilla.org Source: security@mozilla.org Type: Third Party Advisory security@mozilla.org Source: security@mozilla.org Type: Third Party Advisory security@mozilla.org Source: CCN Type: IBM Security Bulletin 6403279 (Security Privileged Identity Manager) IBM Security Privileged Identity Manager is affected by security vulnerabilities Source: CCN Type: IBM Security Bulletin 6403293 (MQ Appliance) IBM MQ Appliance is affected by multiple nss and nspr vulnerabilities Source: CCN Type: IBM Security Bulletin 6457719 (Security Identity Governance and Intelligence) IBM has announced a release for IBM Security Identity Governance and Intelligence in response to a security vulnerability (CVE-2019-17006, CVE-2019-17023, CVE-2020-12403) Source: CCN Type: Mozilla Foundation Security Advisory 2020-01 Security Vulnerabilities fixed in Firefox 72 Source: security@mozilla.org Type: Vendor Advisory security@mozilla.org | ||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration RedHat 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||
BACK |