Vulnerabilities > CVE-2020-12401 - Information Exposure Through Discrepancy vulnerability in Mozilla Firefox

047910
CVSS 4.7 - MEDIUM
Attack vector
LOCAL
Attack complexity
HIGH
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
local
high complexity
mozilla
CWE-203

Summary

During ECDSA signature generation, padding applied in the nonce designed to ensure constant-time scalar multiplication was removed, resulting in variable-time execution dependent on secret data. This vulnerability affects Firefox < 80 and Firefox for Android < 80.

Vulnerable Configurations

Part Description Count
Application
Mozilla
674

Common Weakness Enumeration (CWE)