CVE-2020-12400: Medium severity ibm cognos analytics vulnerability
A side-channel flaw was found in NSS, in the way P-384 and P-521 curves are used in the generation of EDSA signatures, leaking partial information about the ECDSA nonce. Given a small number of ECDSA signatures, this information can be used to steal the private key. The highest threat from this vulnerability is to data confidentiality.
Other sources
As per the researcher:
During our analysis to several cryptographic libraries we focused on NIST curve P-256 code paths and have found that your library is potentially vulnerable because the projective to affine coordinates conversion uses a side-channel vulnerable modular inversion function.
— Red Hat
Mozilla Network Security Services (NSS), as used in Mozilla Firefox could allow a local authenticated attacker to obtain sensitive information, caused by a side-channel flaw in the way P-384 and P-521 curves are used in the generation of EDSA signatures. An attacker could exploit this vulnerability to extract pirate keys and obtain sensitive information.
— IBM
When converting coordinates from projective to affine, the modular inversion was not performed in constant time, resulting in a possible timing-based side channel attack.
Affected Software
Remediation
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2020-12400?
CVE-2020-12400 is a vulnerability in Mozilla Network Security Services (NSS) that allows a local authenticated attacker to obtain sensitive information.
How does CVE-2020-12400 impact Mozilla Firefox?
CVE-2020-12400 could allow a local authenticated attacker to obtain sensitive information in Mozilla Firefox.
How can an attacker exploit CVE-2020-12400?
An attacker can exploit CVE-2020-12400 by leveraging a side-channel flaw in the way P-384 and P-521 curves are used in the generation of EDSA signatures.
What is the severity of CVE-2020-12400?
The severity of CVE-2020-12400 is medium, with a CVSS score of 4.4.
How can I fix CVE-2020-12400?
To fix CVE-2020-12400, it is recommended to update Mozilla Firefox to version 80 or apply the necessary patches provided by the vendor.