CVE-2020-12402

CVSS v3.1 4.4 (Medium)
44% Progress
CVSS v2.0 1.2 (Low)
12% Progress
EPSS 0.07 % (30th)
0.07% Progress
Affected Products 4
Advisories 24

During RSA key generation, bignum implementations used a variation of the Binary Extended Euclidean Algorithm which entailed significantly input-dependent flow. This allowed an attacker able to perform electromagnetic-based side channel attacks to record traces leading to the recovery of the secret primes. Note: An unmodified Firefox browser does not generate RSA keys in normal operation and is not affected, but products built on top of it might. This vulnerability affects Firefox < 78.

Weaknesses
CWE-203
Observable Discrepancy
CVE Status
PUBLISHED
CNA
Mozilla Corporation
Published Date
2020-07-09 15:15:10
(4 years ago)
Updated Date
2023-11-07 03:15:24
(10 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Mozilla Firefox prior 78.0 version cpe:2.3:a:mozilla:firefox < 78.0

Configuration #2

    CPE23 From Up To
  Fedoraproject Fedora 32 cpe:2.3:o:fedoraproject:fedora:32
  Opensuse Leap 15.1 cpe:2.3:o:opensuse:leap:15.1
  Opensuse Leap 15.2 cpe:2.3:o:opensuse:leap:15.2

Configuration #3

    CPE23 From Up To
  Debian Linux 9.0 cpe:2.3:o:debian:debian_linux:9.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...