cbcvebase.
CVE-2020-12402
published 2020-07-09

CVE-2020-12402: During RSA key generation, bignum implementations used a variation of the Binary Extended Euclidean Algorithm which entailed significantly input-dependent…

PriorityP417medium4.4CVSS 3.1
AVLACHPRLUIRSUCHINAN
EPSS
0.34%
26.0th percentile
During RSA key generation, bignum implementations used a variation of the Binary Extended Euclidean Algorithm which entailed significantly input-dependent flow. This allowed an attacker able to perform electromagnetic-based side channel attacks to record traces leading to the recovery of the secret primes. *Note:* An unmodified Firefox browser does not generate RSA keys in normal operation and is not affected, but products built on top of it might. This vulnerability affects Firefox < 78.

Affected

12 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiannss< nss 2:3.53.1-1 (bookworm)nss 2:3.53.1-1 (bookworm)
fedoraprojectfedora
mozillafirefox< 78.078.0
mozillafirefox
mozillafirefox>= unspecified < 7878
mozillanss>= 0 < 2:3.53.1-12:3.53.1-1
mozillanss>= 0 < 2:3.53.1-12:3.53.1-1
mozillanss>= 0 < 2:3.53.1-12:3.53.1-1
mozillanss>= 0 < 2:3.53.1-12:3.53.1-1
opensuseleap
opensuseleap

CVSS provenance

nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N
nvdv2.01.2LOWAV:L/AC:H/Au:N/C:P/I:N/A:N
osv4.4MEDIUM
vendor_oracle7.5HIGH
vendor_debian4.4MEDIUM
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.