cbcvebase.
CVE-2020-12403
published 2021-05-27

CVE-2020-12403: A flaw was found in the way CHACHA20-POLY1305 was implemented in NSS in versions before 3.55. When using multi-part Chacha20, it could cause out-of-bounds…

PriorityP347critical9.1CVSS 3.1
AVNACLPRNUINSUCHINAH
EPSS
1.54%
72.1th percentile
A flaw was found in the way CHACHA20-POLY1305 was implemented in NSS in versions before 3.55. When using multi-part Chacha20, it could cause out-of-bounds reads. This issue was fixed by explicitly disabling multi-part ChaCha20 (which was not functioning correctly) and strictly enforcing tag length. The highest threat from this vulnerability is to confidentiality and system availability.

Affected

10 ranges
VendorProductVersion rangeFixed in
debiannss< nss 2:3.55-1 (bookworm)nss 2:3.55-1 (bookworm)
mozillanss< 3.553.55
mozillanss
mozillanss>= 0 < 2:3.55-12:3.55-1
mozillanss>= 0 < 2:3.55-12:3.55-1
mozillanss>= 0 < 2:3.55-12:3.55-1
mozillanss>= 0 < 2:3.55-12:3.55-1
msrccbl2_nss_3.44-10_on_cbl_mariner_2.0
msrccm1_nss_3.44-6_on_cbl_mariner_1.0
paloaltopan-os

CVSS provenance

nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:P
osv9.1CRITICAL
vendor_debian9.1CRITICAL
vendor_msrc9.1CRITICAL
vendor_redhat9.1CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.