Impact
The vulnerability exists in the Mbed TLS 3.6.x series before 3.6.7 and the 4.1.x series before 4.1.2. When a TLS 1.3 client uses these library versions, it accepts a HelloRetryRequest that contains an elliptic‑curve group not advertised in the original ClientHello. As a result, the client may negotiate a key‑exchange group it did not declare support for. The impact is confined to potential handshake failures or undesirable key‑exchange behavior, and there is no evidence of data exposure, code execution or other severe consequences (CWE‑669).
Affected Systems
TrustedFirmware’s Mbed TLS library in its 3.6.x releases prior to 3.6.7 and 4.1.x releases prior to 4.1.2 is affected. Any system that incorporates these library versions and initiates TLS 1.3 handshakes with a server capable of issuing unsuitable HelloRetryRequest messages may experience this flaw.
Risk and Exploitability
Attackers could trigger the flaw by acting as a TLS 1.3 server that issues a HelloRetryRequest with an unadvertised group. When such a request reaches an affected client, the client will accept it, potentially leading to a failed handshake or the use of an unintended cryptographic group. The CVSS score of 3.7 reflects a low severity, the EPSS score of <1% indicates a very low exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog.
OpenCVE Enrichment