VYPR
Critical severity9.1NVD Advisory· Published Apr 3, 2024· Updated Jun 17, 2026

CVE-2024-30166

CVE-2024-30166

Description

In Mbed TLS 3.3.0 through 3.5.2 before 3.6.0, a malicious client can cause information disclosure or a denial of service because of a stack buffer over-read (of less than 256 bytes) in a TLS 1.3 server via a TLS 3.1 ClientHello.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Mbed TLS/Mbed TLSdescription
  • Arm/MbedTLSllm-fuzzy2 versions
    3.3.0 - 3.5.2+ 1 more
    • (no CPE)range: 3.3.0 - 3.5.2
    • cpe:2.3:a:trustedfirmware:mbed_tls:*:*:*:*:*:*:*:*range: >=3.3.0,<3.6.0

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.