VDB

CVE-2022-35409

CVE-2022-35409 PUBLISHED

An issue was discovered in Mbed TLS before 2.28.1 and 3.x before 3.2.0. In some configurations, an unauthenticated attacker can send an invalid ClientHello message to a DTLS server that causes a heap-based buffer over-read of up to 255 bytes. This can cause a server crash or possibly information disclosure based on error responses. Affected configurations have MBEDTLS_SSL_DTLS_CLIENT_PORT_REUSE enabled and MBEDTLS_SSL_IN_CONTENT_LEN less than a threshold that depends on the configuration: 258 bytes if using mbedtls_ssl_cookie_check, and possibly up to 571 bytes with a custom cookie check function.

EPSS 2.05% · 84.2th percentile

Risk Scores

EPSS Score
2.05%
84.2th percentile

Affected Products

VendorProductVersions
debiandebian_linux10.0
n/an/a*
armmbed_tls0, 3.0.0

Timeline

  • Jul 15, 2022 CVE Published
  • Jul 16, 2022 EPSS Score
  • Sep 1, 2022 EPSS Score
  • Oct 18, 2022 EPSS Score
  • Jan 20, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Mar 8, 2023 EPSS Score
  • Apr 24, 2023 EPSS Score
  • Jun 10, 2023 EPSS Score
  • Jul 27, 2023 EPSS Score
  • Oct 29, 2023 EPSS Score
  • Dec 15, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›