Medium severity6.5NVD Advisory· Published Jan 8, 2020· Updated Jun 17, 2026
CVE-2019-17023
CVE-2019-17023
Description
After a HelloRetryRequest has been sent, the client may negotiate a lower protocol that TLS 1.3, resulting in an invalid state transition in the TLS State Machine. If the client gets into this state, incoming Application Data records will be ignored. This vulnerability affects Firefox < 72.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
13<72+ 2 more
- (no CPE)range: <72
- (no CPE)range: before 72
- cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*range: <72.0
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*+ 4 more
- cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*
- osv-coords2 versionspkg:rpm/opensuse/firefox-esr&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/MozillaFirefox&distro=openSUSE%20Tumbleweed
< 128.5.1-1.1+ 1 more
- (no CPE)range: < 128.5.1-1.1
- (no CPE)range: < 92.0-1.2
Patches
Vulnerability mechanics
References
5- usn.ubuntu.com/4234-1/nvdThird Party Advisory
- usn.ubuntu.com/4397-1/nvdThird Party Advisory
- www.debian.org/security/2020/dsa-4726nvdThird Party Advisory
- www.mozilla.org/security/advisories/mfsa2020-01/nvdVendor Advisory
- bugzilla.mozilla.org/show_bug.cginvdIssue TrackingPermissions Required
News mentions
0No linked articles in our index yet.