Lucene search

K
redhatcveRedhat.comRH:CVE-2019-17023
HistoryJan 15, 2020 - 9:58 a.m.

CVE-2019-17023

2020-01-1509:58:33
redhat.com
access.redhat.com
10

0.002 Low

EPSS

Percentile

59.8%

A protocol downgrade flaw was found in Network Security Services (NSS). After a HelloRetryRequest has been sent, the client may negotiate a lower protocol than TLS 1.3, resulting in an invalid state transition in the TLS State Machine. If the client gets into this state, incoming Application Data records will be ignored.