Security Advisory

CVE-2019-17023

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2020-01-08 21:30:29
Last updated 2024-08-05 01:24:48
Assigner mozilla
State PUBLISHED

Description

After a HelloRetryRequest has been sent, the client may negotiate a lower protocol that TLS 1.3, resulting in an invalid state transition in the TLS State Machine. If the client gets into this state, incoming Application Data records will be ignored. This vulnerability affects Firefox < 72.