CVE-2023-6135
nss: vulnerable to Minerva side-channel information leak
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Multiple NSS NIST curves were susceptible to a side-channel attack known as "Minerva". This attack could potentially allow an attacker to recover the private key. This vulnerability affects Firefox < 121.
MĂșltiples curvas NSS NIST fueron susceptibles a un ataque de canal lateral conocido como "Minerva". Este ataque podrĂa permitir potencialmente que un atacante recupere la clave privada. Esta vulnerabilidad afecta a Firefox < 121.
The Network Security Services (NSS) package contains a vulnerability that exposes a side-channel information leak. This weakness enables a local attacker to capture several thousand usages of a signature, allowing them to utilize this information to recover portions of an ECDSA private key.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2023-11-14 CVE Reserved
- 2023-12-19 CVE Published
- 2024-08-27 CVE Updated
- 2024-11-18 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
- CWE-203: Observable Discrepancy
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
https://security.gentoo.org/glsa/202401-10 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.mozilla.org/security/advisories/mfsa2023-56 | 2024-01-07 | |
https://access.redhat.com/security/cve/CVE-2023-6135 | 2024-04-04 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2249906 | 2024-04-04 | |
https://people.redhat.com/~hkario/marvin | 2024-04-04 |