An issue was discovered in Mbed TLS through 3.5.1. In mbedtls_ssl_session_reset, the maximum negotiable TLS version is mishandled. For example, if the last connection negotiated TLS 1.2, then 1.2 becomes the new maximum.
This Cyber News was published on www.tenable.com. Publication date: Mon, 22 Jan 2024 00:46:03 +0000