CVE-2023-52353 | mbed TLS up to 3.5.1 mbedtls_ssl_session_reset session fixiation (Issue 8654 / Nessus ID 211939)
A vulnerability was found in mbed TLS up to 3.5.1. It has been classified as critical. Affected is the function mbedtls_ssl_session_reset. The manipulation leads to session fixiation.
This vulnerability is traded as CVE-2023-52353. It is possible to launch the attack remotely. There is no exploit available.