CVE-2020-6829

Description

When performing EC scalar point multiplication, the wNAF point multiplication algorithm was used; which leaked partial information about the nonce used during signature generation. Given an electro-magnetic trace of a few signature generations, the private key could have been computed. This vulnerability affects Firefox < 80 and Firefox for Android < 80.

Risk Information

Base Score
5.3
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS Score
Exploitation Probability
0.367

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities fixed in Mozilla Firefox (80.0)Windows
Multiple vulnerabilities fixed in Mozilla Firefox (x64) (80.0)Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.2.4Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 12.0.3Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 10.5Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 10.6Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 11.1Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 11.2Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 11.3Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 11.4Windows
Multiple Vulnerabilities are affected in IBM Security Guardium 11.0Windows
Multiple vulnerabilities are fixed in Mozilla Firefox For Mac (80.0)Mac
Multiple vulnerabilities are fixed in Mozilla Firefox For Mac (80.0.1)Mac
Multiple Vulnerabilities are affected in Mozilla Firefox for Mac 25.0Mac
Multiple Vulnerabilities are affected in Mozilla Firefox for Mac *Mac
Network Security Service library (USN-4455-1) libnss3_3.35-2ubuntu2.11_i386.debLinux
Network Security Service library (USN-4455-1) libnss3_3.35-2ubuntu2.11_amd64.debLinux
Network Security Service library (USN-4455-1) libnss3_3.49.1-1ubuntu1.4_i386.debLinux
Network Security Service library (USN-4455-1) libnss3_3.49.1-1ubuntu1.4_amd64.debLinux
Network Security Service library (USN-4455-1) libnss3_3.28.4-0ubuntu0.16.04.13_i386.debLinux
Network Security Service library (USN-4455-1) libnss3_3.28.4-0ubuntu0.16.04.13_amd64.debLinux
Mozilla Open Source web browser (USN-4474-1) firefox_80.0+build2-0ubuntu0.16.04.1_i386.debLinux
Mozilla Open Source web browser (USN-4474-1) firefox_80.0+build2-0ubuntu0.16.04.1_amd64.debLinux
Mozilla Open Source web browser (USN-4474-1) firefox_80.0+build2-0ubuntu0.18.04.1_i386.debLinux
Mozilla Open Source web browser (USN-4474-1) firefox_80.0+build2-0ubuntu0.18.04.1_amd64.debLinux
Mozilla Open Source web browser (USN-4474-1) firefox_80.0+build2-0ubuntu0.20.04.1_amd64.debLinux
(RHSA-2020:4076) nss and nspr security, bug fix, and enhancement update nspr-4.25.0-2.el7_9.i686.rpmLinux
(RHSA-2020:4076) nss and nspr security, bug fix, and enhancement update nspr-4.25.0-2.el7_9.x86_64.rpmLinux
(RHSA-2020:4076) nss and nspr security, bug fix, and enhancement update nspr-devel-4.25.0-2.el7_9.i686.rpmLinux
(RHSA-2020:4076) nss and nspr security, bug fix, and enhancement update nspr-devel-4.25.0-2.el7_9.x86_64.rpmLinux
(RHSA-2020:4076) nss and nspr security, bug fix, and enhancement update nss-3.53.1-3.el7_9.i686.rpmLinux
(RHSA-2020:4076) nss and nspr security, bug fix, and enhancement update nss-3.53.1-3.el7_9.x86_64.rpmLinux
(RHSA-2020:4076) nss and nspr security, bug fix, and enhancement update nss-devel-3.53.1-3.el7_9.i686.rpmLinux
(RHSA-2020:4076) nss and nspr security, bug fix, and enhancement update nss-devel-3.53.1-3.el7_9.x86_64.rpmLinux
(RHSA-2020:4076) nss and nspr security, bug fix, and enhancement update nss-pkcs11-devel-3.53.1-3.el7_9.i686.rpmLinux
(RHSA-2020:4076) nss and nspr security, bug fix, and enhancement update nss-pkcs11-devel-3.53.1-3.el7_9.x86_64.rpmLinux
(RHSA-2020:4076) nss and nspr security, bug fix, and enhancement update nss-softokn-3.53.1-6.el7_9.i686.rpmLinux
(RHSA-2020:4076) nss and nspr security, bug fix, and enhancement update nss-softokn-3.53.1-6.el7_9.x86_64.rpmLinux
(RHSA-2020:4076) nss and nspr security, bug fix, and enhancement update nss-softokn-devel-3.53.1-6.el7_9.i686.rpmLinux
(RHSA-2020:4076) nss and nspr security, bug fix, and enhancement update nss-softokn-devel-3.53.1-6.el7_9.x86_64.rpmLinux
(RHSA-2020:4076) nss and nspr security, bug fix, and enhancement update nss-softokn-freebl-3.53.1-6.el7_9.i686.rpmLinux
(RHSA-2020:4076) nss and nspr security, bug fix, and enhancement update nss-softokn-freebl-3.53.1-6.el7_9.x86_64.rpmLinux
(RHSA-2020:4076) nss and nspr security, bug fix, and enhancement update nss-softokn-freebl-devel-3.53.1-6.el7_9.i686.rpmLinux
(RHSA-2020:4076) nss and nspr security, bug fix, and enhancement update nss-softokn-freebl-devel-3.53.1-6.el7_9.x86_64.rpmLinux
(RHSA-2020:4076) nss and nspr security, bug fix, and enhancement update nss-sysinit-3.53.1-3.el7_9.x86_64.rpmLinux
(RHSA-2020:4076) nss and nspr security, bug fix, and enhancement update nss-tools-3.53.1-3.el7_9.x86_64.rpmLinux
(RHSA-2020:4076) nss and nspr security, bug fix, and enhancement update nss-util-3.53.1-1.el7_9.i686.rpmLinux
(RHSA-2020:4076) nss and nspr security, bug fix, and enhancement update nss-util-3.53.1-1.el7_9.x86_64.rpmLinux
(RHSA-2020:4076) nss and nspr security, bug fix, and enhancement update nss-util-devel-3.53.1-1.el7_9.i686.rpmLinux
(RHSA-2020:4076) nss and nspr security, bug fix, and enhancement update nss-util-devel-3.53.1-1.el7_9.x86_64.rpmLinux
Nspr update (ELSA-2020-4076) nspr-4.25.0-2.el7_9.x86_64.rpmLinux
Nspr-devel update (ELSA-2020-4076) nspr-devel-4.25.0-2.el7_9.x86_64.rpmLinux
Nss update (ELSA-2020-4076) nss-3.53.1-3.el7_9.x86_64.rpmLinux
Nss-devel update (ELSA-2020-4076) nss-devel-3.53.1-3.el7_9.x86_64.rpmLinux
Nss-pkcs11-devel update (ELSA-2020-4076) nss-pkcs11-devel-3.53.1-3.el7_9.x86_64.rpmLinux
Nss-softokn update (ELSA-2020-4076) nss-softokn-3.53.1-6.0.1.el7_9.x86_64.rpmLinux
Nss-softokn-devel update (ELSA-2020-4076) nss-softokn-devel-3.53.1-6.0.1.el7_9.x86_64.rpmLinux
Nss-softokn-freebl update (ELSA-2020-4076) nss-softokn-freebl-3.53.1-6.0.1.el7_9.x86_64.rpmLinux
Nss-softokn-freebl-devel update (ELSA-2020-4076) nss-softokn-freebl-devel-3.53.1-6.0.1.el7_9.x86_64.rpmLinux
Nss-sysinit update (ELSA-2020-4076) nss-sysinit-3.53.1-3.el7_9.x86_64.rpmLinux
Nss-tools update (ELSA-2020-4076) nss-tools-3.53.1-3.el7_9.x86_64.rpmLinux
Nss-util update (ELSA-2020-4076) nss-util-3.53.1-1.el7_9.x86_64.rpmLinux
Nss-util-devel update (ELSA-2020-4076) nss-util-devel-3.53.1-1.el7_9.x86_64.rpmLinux
Nspr update (ELSA-2020-4076) nspr-4.25.0-2.el7_9.i686.rpmLinux
Nspr-devel update (ELSA-2020-4076) nspr-devel-4.25.0-2.el7_9.i686.rpmLinux
Nss update (ELSA-2020-4076) nss-3.53.1-3.el7_9.i686.rpmLinux
Nss-devel update (ELSA-2020-4076) nss-devel-3.53.1-3.el7_9.i686.rpmLinux
Nss-pkcs11-devel update (ELSA-2020-4076) nss-pkcs11-devel-3.53.1-3.el7_9.i686.rpmLinux
Nss-softokn update (ELSA-2020-4076) nss-softokn-3.53.1-6.0.1.el7_9.i686.rpmLinux
Nss-softokn-devel update (ELSA-2020-4076) nss-softokn-devel-3.53.1-6.0.1.el7_9.i686.rpmLinux
Nss-softokn-freebl update (ELSA-2020-4076) nss-softokn-freebl-3.53.1-6.0.1.el7_9.i686.rpmLinux
Nss-softokn-freebl-devel update (ELSA-2020-4076) nss-softokn-freebl-devel-3.53.1-6.0.1.el7_9.i686.rpmLinux
Nss-util update (ELSA-2020-4076) nss-util-3.53.1-1.el7_9.i686.rpmLinux
Nss-util-devel update (ELSA-2020-4076) nss-util-devel-3.53.1-1.el7_9.i686.rpmLinux
(RHSA-2021:0538) nss security and bug fix update nss-3.53.1-17.el8_3.i686.rpmLinux
(RHSA-2021:0538) nss security and bug fix update nss-3.53.1-17.el8_3.x86_64.rpmLinux
(RHSA-2021:0538) nss security and bug fix update nss-debugsource-3.53.1-17.el8_3.i686.rpmLinux
(RHSA-2021:0538) nss security and bug fix update nss-debugsource-3.53.1-17.el8_3.x86_64.rpmLinux
(RHSA-2021:0538) nss security and bug fix update nss-devel-3.53.1-17.el8_3.i686.rpmLinux
(RHSA-2021:0538) nss security and bug fix update nss-devel-3.53.1-17.el8_3.x86_64.rpmLinux
(RHSA-2021:0538) nss security and bug fix update nss-softokn-3.53.1-17.el8_3.i686.rpmLinux
(RHSA-2021:0538) nss security and bug fix update nss-softokn-3.53.1-17.el8_3.x86_64.rpmLinux
(RHSA-2021:0538) nss security and bug fix update nss-softokn-devel-3.53.1-17.el8_3.i686.rpmLinux
(RHSA-2021:0538) nss security and bug fix update nss-softokn-devel-3.53.1-17.el8_3.x86_64.rpmLinux
(RHSA-2021:0538) nss security and bug fix update nss-softokn-freebl-3.53.1-17.el8_3.i686.rpmLinux
(RHSA-2021:0538) nss security and bug fix update nss-softokn-freebl-3.53.1-17.el8_3.x86_64.rpmLinux
(RHSA-2021:0538) nss security and bug fix update nss-softokn-freebl-devel-3.53.1-17.el8_3.i686.rpmLinux
(RHSA-2021:0538) nss security and bug fix update nss-softokn-freebl-devel-3.53.1-17.el8_3.x86_64.rpmLinux
(RHSA-2021:0538) nss security and bug fix update nss-sysinit-3.53.1-17.el8_3.x86_64.rpmLinux
(RHSA-2021:0538) nss security and bug fix update nss-tools-3.53.1-17.el8_3.x86_64.rpmLinux
(RHSA-2021:0538) nss security and bug fix update nss-util-3.53.1-17.el8_3.i686.rpmLinux
(RHSA-2021:0538) nss security and bug fix update nss-util-3.53.1-17.el8_3.x86_64.rpmLinux
(RHSA-2021:0538) nss security and bug fix update nss-util-devel-3.53.1-17.el8_3.i686.rpmLinux
(RHSA-2021:0538) nss security and bug fix update nss-util-devel-3.53.1-17.el8_3.x86_64.rpmLinux
Nss update (ELSA-2021-0538) nss-3.53.1-17.el8_3.i686.rpmLinux
Nss update (ELSA-2021-0538) nss-3.53.1-17.el8_3.x86_64.rpmLinux
Nss-devel update (ELSA-2021-0538) nss-devel-3.53.1-17.el8_3.i686.rpmLinux
Nss-devel update (ELSA-2021-0538) nss-devel-3.53.1-17.el8_3.x86_64.rpmLinux
Nss-softokn update (ELSA-2021-0538) nss-softokn-3.53.1-17.el8_3.i686.rpmLinux
Nss-softokn update (ELSA-2021-0538) nss-softokn-3.53.1-17.el8_3.x86_64.rpmLinux
Nss-softokn-devel update (ELSA-2021-0538) nss-softokn-devel-3.53.1-17.el8_3.i686.rpmLinux
Nss-softokn-devel update (ELSA-2021-0538) nss-softokn-devel-3.53.1-17.el8_3.x86_64.rpmLinux
Nss-softokn-freebl update (ELSA-2021-0538) nss-softokn-freebl-3.53.1-17.el8_3.i686.rpmLinux
Nss-softokn-freebl update (ELSA-2021-0538) nss-softokn-freebl-3.53.1-17.el8_3.x86_64.rpmLinux
Nss-softokn-freebl-devel update (ELSA-2021-0538) nss-softokn-freebl-devel-3.53.1-17.el8_3.i686.rpmLinux
Nss-softokn-freebl-devel update (ELSA-2021-0538) nss-softokn-freebl-devel-3.53.1-17.el8_3.x86_64.rpmLinux
Nss-sysinit update (ELSA-2021-0538) nss-sysinit-3.53.1-17.el8_3.x86_64.rpmLinux
Nss-tools update (ELSA-2021-0538) nss-tools-3.53.1-17.el8_3.x86_64.rpmLinux
Nss-util update (ELSA-2021-0538) nss-util-3.53.1-17.el8_3.i686.rpmLinux
Nss-util update (ELSA-2021-0538) nss-util-3.53.1-17.el8_3.x86_64.rpmLinux
Nss-util-devel update (ELSA-2021-0538) nss-util-devel-3.53.1-17.el8_3.i686.rpmLinux
Nss-util-devel update (ELSA-2021-0538) nss-util-devel-3.53.1-17.el8_3.x86_64.rpmLinux
(CESA-2020:4076) nss and nspr security, bug fix, and enhancement update nss-3.53.1-3.el7_9.i686.rpmLinux
(CESA-2020:4076) nss and nspr security, bug fix, and enhancement update nss-3.53.1-3.el7_9.x86_64.rpmLinux
(CESA-2020:4076) nss and nspr security, bug fix, and enhancement update nss-devel-3.53.1-3.el7_9.i686.rpmLinux
(CESA-2020:4076) nss and nspr security, bug fix, and enhancement update nss-devel-3.53.1-3.el7_9.x86_64.rpmLinux
(CESA-2020:4076) nss and nspr security, bug fix, and enhancement update nss-pkcs11-devel-3.53.1-3.el7_9.i686.rpmLinux
(CESA-2020:4076) nss and nspr security, bug fix, and enhancement update nss-pkcs11-devel-3.53.1-3.el7_9.x86_64.rpmLinux
(CESA-2020:4076) nss and nspr security, bug fix, and enhancement update nss-softokn-3.53.1-6.el7_9.i686.rpmLinux
(CESA-2020:4076) nss and nspr security, bug fix, and enhancement update nss-softokn-3.53.1-6.el7_9.x86_64.rpmLinux
(CESA-2020:4076) nss and nspr security, bug fix, and enhancement update nss-softokn-devel-3.53.1-6.el7_9.i686.rpmLinux
(CESA-2020:4076) nss and nspr security, bug fix, and enhancement update nss-softokn-devel-3.53.1-6.el7_9.x86_64.rpmLinux
(CESA-2020:4076) nss and nspr security, bug fix, and enhancement update nss-softokn-freebl-3.53.1-6.el7_9.i686.rpmLinux
(CESA-2020:4076) nss and nspr security, bug fix, and enhancement update nss-softokn-freebl-3.53.1-6.el7_9.x86_64.rpmLinux
(CESA-2020:4076) nss and nspr security, bug fix, and enhancement update nss-softokn-freebl-devel-3.53.1-6.el7_9.i686.rpmLinux
(CESA-2020:4076) nss and nspr security, bug fix, and enhancement update nss-softokn-freebl-devel-3.53.1-6.el7_9.x86_64.rpmLinux
(CESA-2020:4076) nss and nspr security, bug fix, and enhancement update nss-sysinit-3.53.1-3.el7_9.x86_64.rpmLinux
(CESA-2020:4076) nss and nspr security, bug fix, and enhancement update nss-tools-3.53.1-3.el7_9.x86_64.rpmLinux
(CESA-2020:4076) nss and nspr security, bug fix, and enhancement update nss-util-3.53.1-1.el7_9.i686.rpmLinux
(CESA-2020:4076) nss and nspr security, bug fix, and enhancement update nss-util-3.53.1-1.el7_9.x86_64.rpmLinux
(CESA-2020:4076) nss and nspr security, bug fix, and enhancement update nss-util-devel-3.53.1-1.el7_9.i686.rpmLinux
(CESA-2020:4076) nss and nspr security, bug fix, and enhancement update nss-util-devel-3.53.1-1.el7_9.x86_64.rpmLinux
(CESA-2020:4076) nss and nspr security, bug fix, and enhancement update nspr-4.25.0-2.el7_9.x86_64.rpmLinux
(CESA-2020:4076) nss and nspr security, bug fix, and enhancement update nspr-devel-4.25.0-2.el7_9.x86_64.rpmLinux
(RHSA-2020:4076)Moderate: and nspr security, bug fix, and enhancement update nspr-debuginfo-4.25.0-2.el7_9.i686.rpmLinux
(RHSA-2020:4076)Moderate: and nspr security, bug fix, and enhancement update nspr-debuginfo-4.25.0-2.el7_9.x86_64.rpmLinux
(RHSA-2020:4076)Moderate: and nspr security, bug fix, and enhancement update nss-debuginfo-3.53.1-3.el7_9.i686.rpmLinux
(RHSA-2020:4076)Moderate: and nspr security, bug fix, and enhancement update nss-debuginfo-3.53.1-3.el7_9.x86_64.rpmLinux
(RHSA-2020:4076)Moderate: and nspr security, bug fix, and enhancement update nss-softokn-debuginfo-3.53.1-6.el7_9.i686.rpmLinux
(RHSA-2020:4076)Moderate: and nspr security, bug fix, and enhancement update nss-softokn-debuginfo-3.53.1-6.el7_9.x86_64.rpmLinux
(RHSA-2020:4076)Moderate: and nspr security, bug fix, and enhancement update nss-util-debuginfo-3.53.1-1.el7_9.i686.rpmLinux
(RHSA-2020:4076)Moderate: and nspr security, bug fix, and enhancement update nss-util-debuginfo-3.53.1-1.el7_9.x86_64.rpmLinux
CVE-2020-6829NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-315672Mozilla Firefox (80.0)
PATCH-315673Mozilla Firefox (x64) (80.0)
PATCH-607000Mozilla Firefox For Mac (124.0)
PATCH-607000Mozilla Firefox For Mac (124.0)
PATCH-611870Mozilla Firefox For Mac (142.0.1)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234