After a HelloRetryRequest has been sent, the client may negotiate a lower protocol that TLS 1.3, resulting in an invalid state transition in the TLS State Machine. If the client gets into this state, incoming Application Data records will be ignored. This vulnerability affects Firefox < 72.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mozilla

Published: 2020-01-08T21:30:29

Updated: 2020-07-18T15:06:08

Reserved: 2019-09-30T00:00:00


Link: CVE-2019-17023

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-01-08T22:15:12.827

Modified: 2023-01-27T18:24:03.227


Link: CVE-2019-17023

JSON object: View

cve-icon Redhat Information

No data.

CWE