CVE-2020-25648
published 2020-10-20CVE-2020-25648: A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a…
PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
3.90%
89.1th percentile
A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library. The highest threat from this vulnerability is to system availability. This flaw affects NSS versions before 3.58.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nss | < nss 2:3.58-1 (bookworm) | nss 2:3.58-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| mozilla | network_security_services | < 3.58 | 3.58 |
| mozilla | nss | >= 0 < 2:3.58-1 | 2:3.58-1 |
| mozilla | nss | >= 0 < 2:3.58-1 | 2:3.58-1 |
| mozilla | nss | >= 0 < 2:3.58-1 | 2:3.58-1 |
| mozilla | nss | >= 0 < 2:3.58-1 | 2:3.58-1 |
| oracle | communications_offline_mediation_controller | — | — |
| oracle | communications_pricing_design_center | — | — |
| oracle | jd_edwards_enterpriseone_tools | < 9.2.6.0 | 9.2.6.0 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
NSS vulnerability
vendor_ubuntu·2022-05-11
CVE-2020-25648 NSS vulnerability
Title: NSS vulnerability
Summary: NSS could be made to stop responding if it received a specially crafted message.
Lenny Wang discovered that NSS incorrectly handled certain
messages. A remote attacker could possibly use this issue to cause
servers compiled with NSS to stop responding, resulting in a denial of service.
Instructions: After a standard system update you need to restart any applications that
use NSS to make all the necessary changes.
Oracle
Oracle Oracle Communications Applications Risk Matrix: Storage & Reporting (NSS) — CVE-2020-25648
vendor_oracle·2021-10-15·CVSS 7.5
CVE-2020-25648 [HIGH] Oracle Oracle Communications Applications Risk Matrix: Storage & Reporting (NSS) — CVE-2020-25648
Oracle Oracle Communications Applications Risk Matrix: Storage & Reporting (NSS) vulnerability
CVE: CVE-2020-25648
CVSS: 7.5
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2021 (OCT 2021)
Oracle
Oracle Oracle Communications Applications Risk Matrix: CNE (NSS) — CVE-2020-25648
vendor_oracle·2021-07-15·CVSS 7.5
CVE-2020-25648 [HIGH] Oracle Oracle Communications Applications Risk Matrix: CNE (NSS) — CVE-2020-25648
Oracle Oracle Communications Applications Risk Matrix: CNE (NSS) vulnerability
CVE: CVE-2020-25648
CVSS: 7.5
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2021 (JUL 2021)
Red Hat
nss: TLS 1.3 CCS flood remote DoS Attack
vendor_redhat·2020-10-19·CVSS 7.5
CVE-2020-25648 [HIGH] CWE-770 nss: TLS 1.3 CCS flood remote DoS Attack
nss: TLS 1.3 CCS flood remote DoS Attack
A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library. The highest threat from this vulnerability is to system availability. This flaw affects NSS versions before 3.58.
A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library. The highest threat from this vulnerability is to system availability.
Statement: This flaw only affects servers that are compiled with the NSS library and when the TLS 1.3 protocol is used.
Package:
Debian
CVE-2020-25648: nss - A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1...
vendor_debian·2020·CVSS 7.5
CVE-2020-25648 [HIGH] CVE-2020-25648: nss - A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1...
A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library. The highest threat from this vulnerability is to system availability. This flaw affects NSS versions before 3.58.
Scope: local
bookworm: resolved (fixed in 2:3.58-1)
bullseye: resolved (fixed in 2:3.58-1)
forky: resolved (fixed in 2:3.58-1)
sid: resolved (fixed in 2:3.58-1)
trixie: resolved (fixed in 2:3.58-1)
GHSA
GHSA-43j5-76vw-pq2j: A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1
ghsa_unreviewed·2022-05-24
CVE-2020-25648 [HIGH] CWE-770 GHSA-43j5-76vw-pq2j: A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1
A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library. The highest threat from this vulnerability is to system availability. This flaw affects NSS versions before 3.58.
OSV
CVE-2020-25648: A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1
osv·2020-10-20·CVSS 7.5
CVE-2020-25648 [HIGH] CVE-2020-25648: A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1
A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library. The highest threat from this vulnerability is to system availability. This flaw affects NSS versions before 3.58.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-25648 nss: TLS 1.3 CCS flood remote DoS Attack [fedora-all]
bugzilla·2020-10-20·CVSS 7.5
CVE-2020-25648 [HIGH] CVE-2020-25648 nss: TLS 1.3 CCS flood remote DoS Attack [fedora-all]
CVE-2020-25648 nss: TLS 1.3 CCS flood remote DoS Attack [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedor
Bugzilla
CVE-2020-25648 nss: TLS 1.3 CCS flood remote DoS Attack
bugzilla·2020-10-12·CVSS 7.5
CVE-2020-25648 [HIGH] CVE-2020-25648 nss: TLS 1.3 CCS flood remote DoS Attack
CVE-2020-25648 nss: TLS 1.3 CCS flood remote DoS Attack
NSS allows an attacker to send CCS messages in a row after ClientHello message. If an attacker put multiple CCS messages in a single tcp packet, the NSS server will stuck in a loop for many times to process the messages.
This issue affects servers which are compiled against the NSS library. Other consumers of NSS like firefox etc are not affected by this flaw.
Discussion:
Upstream patch: https://hg.mozilla.org/projects/nss/rev/57bbefa793232586d27cee83e74411171e128361
Upstream bug (currently private): https://bugzilla.mozilla.org/show_bug.cgi?id=1641480
---
Statement:
This flaw only affects servers that are compiled with the NSS library and when the TLS 1.3 protocol is used.
---
External References:
https://developer.mozilla.
Bugzilla
Mozilla NSS TLS 1.3 CCS Flood remote DoS Attack
bugzilla·2020-05-28
Mozilla NSS TLS 1.3 CCS Flood remote DoS Attack
Mozilla NSS TLS 1.3 CCS Flood remote DoS Attack
Created attachment 9152323
PoC
User Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36
Steps to reproduce:
Step 1. Checkout the latest version of NSS code and build it. Revision ID: 661e3e3f6ba515a36fc97038164979a216c9f87b
Step 2. Run ssl_gtests.sh test to create the data selfserv tool needed.
```shell
HOST=localhost DOMSUF=localdomain USE_64=1 ./nss/tests/ssl_gtests/ssl_gtests.sh
```
Step 3. Run slefserv in TLS 1.3 mode.
```shell
NSS_DIR="$(pwd)/dist/$(cat dist/latest)"
LD_LIBRARY_PATH="$NSS_DIR/lib" "$NSS_DIR/bin/selfserv" -n rsa -p 4433 -d ~/nss-dev/tests_results/security/localhost.1/ssl_gtests/ -v -V tls1.3:tls1.3
```
Step 4. Config environment for PoC (
https://bugzilla.redhat.com/show_bug.cgi?id=1887319https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.58_release_noteshttps://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2023/10/msg00039.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ERA5SVJQXQMDGES7RIT4F4NQVLD35RXN/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HRM53IQCPZT2US3M7JXTP6I6IBA5RGOD/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RPOLN6DJUYQ3QBQEGLZGV73SNIPK7GHV/https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1887319https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.58_release_noteshttps://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2023/10/msg00039.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ERA5SVJQXQMDGES7RIT4F4NQVLD35RXN/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HRM53IQCPZT2US3M7JXTP6I6IBA5RGOD/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RPOLN6DJUYQ3QBQEGLZGV73SNIPK7GHV/https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.html
2020-10-20
Published