4.3
CVSSv3

CVE-2023-6135

Published: 19/12/2023 Updated: 07/01/2024
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Multiple NSS NIST curves were susceptible to a side-channel attack known as "Minerva". This attack could potentially allow an malicious user to recover the private key. This vulnerability affects Firefox < 121.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox

Vendor Advisories

Debian Bug report logs - #1059054 nss: CVE-2023-6135 Package: src:nss; Maintainer for src:nss is Maintainers of Mozilla-related packages &lt;team+pkg-mozilla@trackerdebianorg&gt;; Reported by: Moritz Mühlenhoff &lt;jmm@inutilorg&gt; Date: Tue, 19 Dec 2023 21:24:01 UTC Severity: grave Tags: security, upstream Found in versio ...
Synopsis Moderate: nss security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for nss is now available for Red Hat Enterprise Linux 92 Extended Update SupportRed Hat Product Security has rated this upd ...
Synopsis Moderate: nss security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for nss is now available for Red Hat Enterprise Linux 9Red Hat Product Security has rated this update as having a security i ...
Synopsis Moderate: nss security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for nss is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security i ...
Synopsis Moderate: nss security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for nss is now available for Red Hat Enterprise Linux 88 Extended Update SupportRed Hat Product Security has rated this upd ...
Multiple NSS NIST curves were susceptible to a side-channel attack known as "Minerva" This attack could potentially allow an attacker to recover the private key This vulnerability affects Firefox &lt; 121 (CVE-2023-6135) ...
Mozilla Foundation Security Advisory 2023-56 Security Vulnerabilities fixed in Firefox 121 Announced December 19, 2023 Impact high Products Firefox Fixed in Firefox 121 ...
Description<!---->The Network Security Services (NSS) package contains a vulnerability that exposes a side-channel information leak This weakness enables a local attacker to capture several thousand usages of a signature, allowing them to utilize this information to recover portions of an ECDSA private keyThe Network Security Services (NSS) packa ...