Impact
Based on the description, the vulnerability involves the TLS 1.3 client from Mbed TLS versions 3.6.x prior to 3.6.7 and 4.1.x prior to 4.1.2 accepting a HelloRetryRequest that specifies an unadvertised group. This means the client may follow a key‑exchange group not advertised in the original client hello. The impact appears limited to possible handshake failures no evidence of remote code execution or data exposure (CWE-669).
Affected Systems
The affected products are TrustedFirmware’s Mbed TLS library versions 3.6.x prior to 3.6.7 and 4.1.x prior to 4.1.2. Any system that incorporates these specific library versions and performs TLS 1.3 handshakes with a server capable of issuing a HelloRetryRequest is potentially vulnerable.
Risk and Exploitability
Based on the description, it is inferred that the likely attack vector involves a malicious or misconfigured TLS 1.3 server that sends a HelloRetryRequest with an unadvertised group, leading the client to accept it. No additional exploitation conditions beyond a standard TLS 1.3 handshake are described, and no evidence of remote code execution or data compromise is provided. The CVSS score of 3.7 indicates low severity, the EPSS score is <1% (~0.00218), and the vulnerability is not listed in CISA’s KEV catalog.
OpenCVE Enrichment