← back
CVE-2024-30166

CVE-2024-30166

CVSS 9.1 CRITICALEPSS 0.7%CWE-121
Vexday Risk Score
28Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 9.1EPSS 0.7%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
03 Apr 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
In Mbed TLS 3.3.0 through 3.5.2 before 3.6.0, a malicious client can cause information disclosure or a denial of service because of a stack buffer over-read (of less than 256 bytes) in a TLS 1.3 server via a TLS 3.1 ClientHello.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Affected products
n/a · n/a