← Back to CVE List

CVE-2024-5814

Published: 2024-08-27T19:15Z
Last Modified: 2024-08-28T12:57Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
A malicious TLS1.2 server can force a TLS1.3 client with downgrade capability to use a ciphersuite that it did not agree to and achieve a successful connection. This is because, aside from the extensions, the client was skipping fully parsing the server hello. https://doi.org/10.46586/tches.v2024.i1.457-500 > MITRE Terms of Use apply – see LICENSE‑MITRE.txt