VDB

CVE-2023-40217

CVE-2023-40217 PUBLISHED CVSS 5.300000190734863 MEDIUM

If a TLS server side socket is created, receives data, and then closes quickly, there's a brief window where the SSLSocket instance detects it as "not connected" and won't initiate a handshake. Buffered data remains readable but unauthenticated if client certificate authentication is expected. This data is limited to the buffer size. An unauthenticated attacker could exploit this vulnerability for revealing sensitive information from the server.

EPSS 0.58% · 69.3th percentile

Risk Scores

CVSS 3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:W/RC:C
EPSS Score
0.58%
69.3th percentile

Affected Products

VendorProductVersions
Cloudflarestream
AWSconnect
ABBABB M2M Gateway ARM600, firmware versions >=4.1.2|<=5.0.3
ABBABB M2M Gateway SW, software versions >=5.0.1|<=5.0.3

Timeline

  • Aug 24, 2023 CVE Published
  • Aug 25, 2023 EPSS Score
  • Sep 27, 2023 EPSS Score
  • Dec 2, 2023 EPSS Score
  • Jan 4, 2024 EPSS Score
  • Feb 6, 2024 EPSS Score
  • Mar 10, 2024 EPSS Score
  • May 16, 2024 EPSS Score
  • Jun 18, 2024 EPSS Score
  • Jul 21, 2024 EPSS Score
  • Aug 23, 2024 EPSS Score
  • Oct 28, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›