Mbed-TLS.mbedtls is vulnerable to Improper Authentication
85
High Risk
Mbed TLS contains an authentication bypass vulnerability in TLS session resumption. Under specific conditions involving TLS 1.3 session tickets, a HelloRetryRequest, and fallback to TLS 1.2, a man-in-the-middle attacker may cause the server to resume a session using an all-zero master secret, potentially bypassing client authentication and inheriting the authenticated client's privileges. The issue affects servers supporting both TLS 1.2 and TLS 1.3 with client authentication and session ticket resumption enabled.
You are affected if you are using a version that falls within the vulnerable range and run an Mbed TLS server with both TLS 1.2 and TLS 1.3 enabled, client authentication, and TLS 1.3 session tickets (especially if HelloRetryRequest can occur on resumption).
Mbed-TLS.mbedtls is vulnerable to Improper Authentication in versions 3.5.0 - 3.6.5 and 4.0.0 - 4.0.0.
Upgrade to a patched version. If this is not possible, disable TLS 1.3 PSK with (EC)DHE key exchange or disable session ticket generation to prevent the vulnerable resumption path.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant