CVE-2023-23759

HIGH

Facebook Fizz < 2023.01.30.00 - Denial of Service via ClientHello Cipher Advertisement Change

Title source: llm
STIX 2.1

Description

There is a vulnerability in the fizz library prior to v2023.01.30.00 where a CHECK failure can be triggered remotely. This behavior requires the client supported cipher advertisement changing between the original ClientHello and the second ClientHello, crashing the process (impact is limited to denial of service).

Scores

CVSS v3 7.5
EPSS 0.0072
EPSS Percentile 49.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-617
Status published
Products (1)
facebook/fizz < 2023.01.30.00
Published May 18, 2023
Tracked Since Feb 18, 2026