nss: ECDSA timing attack mitigation bypass
Published Oct 8, 2020
4.7
MEDIUMCVSS 3.1
EPSS 0.32%
Description
During ECDSA signature generation, padding applied in the nonce designed to ensure constant-time scalar multiplication was removed, resulting in variable-time execution dependent on secret data. This vulnerability affects Firefox < 80 and Firefox for Android < 80.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<80
- Version
-
- Version unspecifiedStatusaffectedConstraints<80
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Mozilla | Firefox | n/a |
| ||||||
| Mozilla | Firefox for Android | n/a |
|
- < 80.0
- < 80.0
No data.
Red Hat Enterprise Linux 7
nspr-0:4.25.0-2.el7_9
Fixed · RHSA-2020:4076
Red Hat Enterprise Linux 7
nss-0:3.53.1-3.el7_9
Fixed · RHSA-2020:4076
Red Hat Enterprise Linux 7
nss-softokn-0:3.53.1-6.el7_9
Fixed · RHSA-2020:4076
Red Hat Enterprise Linux 7
nss-util-0:3.53.1-1.el7_9
Fixed · RHSA-2020:4076
Red Hat Enterprise Linux 8
nss-0:3.53.1-17.el8_3
Fixed · RHSA-2021:0538
Red Hat OpenShift Do
openshiftdo/odo-init-image-rhel7:1.1.3-2
Fixed · RHSA-2021:0949
Red Hat Enterprise Linux 5
nss
Out of support scope
Red Hat Enterprise Linux 6
nss
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | nspr-0:4.25.0-2.el7_9 | Fixed | RHSA-2020:4076 |
| Red Hat Enterprise Linux 7 | nss-0:3.53.1-3.el7_9 | Fixed | RHSA-2020:4076 |
| Red Hat Enterprise Linux 7 | nss-softokn-0:3.53.1-6.el7_9 | Fixed | RHSA-2020:4076 |
| Red Hat Enterprise Linux 7 | nss-util-0:3.53.1-1.el7_9 | Fixed | RHSA-2020:4076 |
| Red Hat Enterprise Linux 8 | nss-0:3.53.1-17.el8_3 | Fixed | RHSA-2021:0538 |
| Red Hat OpenShift Do | openshiftdo/odo-init-image-rhel7:1.1.3-2 | Fixed | RHSA-2021:0949 |
| Red Hat Enterprise Linux 5 | nss | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | nss | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This is a side channel attack which can used to exact pirate keys when ECDSA signatures are being generated. This attack is only feasible when the attacker is local to the machine or in certain cross-VM scenarios where the signature is being generated. Attacks over the network or via the internet are not feasible.
Red Hat mitigation
This is a side channel attack which can used to exact pirate keys when ECDSA signatures are being generated. This attack is only feasible when the attacker is local to the machine or in certain cross-VM scenarios where the signature is being generated. Attacks over the network or via the internet are not feasible.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
1 other source (Red Hat) ▾
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N
No CVSS v3.0 score for this CVE.
AV:L/AC:M/Au:N/C:P/I:N/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 4, 2026.
Score over time
2021-2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (14 key points)
Flat stretches are collapsed. Showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 4, 2026 | 0.32% (0.00323) | 23.10th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.31% (0.00309) | 22.38th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.07% (0.00066) | 17.84th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.05% (0.00046) | 19.04th | v3 (v2023.03.01) |
| May 7, 2024 | 0.05% (0.00046) | 16.01th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.05% (0.00046) | 14.00th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.36% (0.01365) | 71.56th | v2 (v2022.01.01) |
| Feb 28, 2023 | 1.36% (0.01365) | 71.53th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.36% (0.01365) | 69.53th | v2 (v2022.01.01) |
| Feb 4, 2022 | 2.74% (0.02737) | 62.78th | v2 (v2022.01.01) |
| Feb 3, 2022 | 6.22% (0.06225) | 82.33th | v1 |
| Jan 6, 2022 | 6.22% (0.06225) | 82.16th | v1 |
| Sep 1, 2021 | 1.46% (0.01458) | 72.29th | v1 |
| Apr 14, 2021 | 1.46% (0.01458) | 0.00th | v1 |
References (9)
- https://access.redhat.com/security/cve/CVE-2020-12401 Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1631573 Issue TrackingPermissions RequiredVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1851294 Issue Tracking
- https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.55_release_notes
- https://lists.debian.org/debian-lts-announce/2023/02/msg00021.html mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2020-12401
- https://www.cve.org/CVERecord?id=CVE-2020-12401
- https://www.mozilla.org/security/advisories/mfsa2020-36/ Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2020-39/ Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2020-12401 | Vendor Advisory | |
| https://bugzilla.mozilla.org/show_bug.cgi?id=1631573 | Issue TrackingPermissions RequiredVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1851294 | Issue Tracking | |
| https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.55_release_notes | ||
| https://lists.debian.org/debian-lts-announce/2023/02/msg00021.html | mailing-list | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-12401 | ||
| https://www.cve.org/CVERecord?id=CVE-2020-12401 | ||
| https://www.mozilla.org/security/advisories/mfsa2020-36/ | Vendor Advisory | |
| https://www.mozilla.org/security/advisories/mfsa2020-39/ | Vendor Advisory |
Change history (0)
No recorded changes yet.