
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-12402 is a side-channel vulnerability discovered in RSA key generation implementations. The vulnerability was disclosed on June 30, 2020, affecting the Network Security Service (NSS) libraries and Firefox versions prior to 78. During RSA key generation, bignum implementations used a variation of the Binary Extended Euclidean Algorithm which had significantly input-dependent flow, making it susceptible to electromagnetic-based side channel attacks (Mozilla Advisory, Ubuntu Notice).
The vulnerability exists in the implementation of mp_gcd and mp_invmod functions, which are based on variations of the Binary Extended Euclidean Algorithm (BEEA). The input-dependent control flow in these functions made them susceptible to various forms of Side Channel Analysis (SCA). The vulnerability allowed attackers capable of performing electromagnetic-based side channel attacks to record traces that could lead to the recovery of secret RSA primes. The peaks in electromagnetic traces identify multi-precision subtractions, while the distance between peaks identifies the number of shifts, enabling complete recovery of RSA primes and thus the secret key (Mozilla Bugzilla).
The vulnerability could allow a local attacker to perform timing attacks and recover RSA keys through electromagnetic-based side channel analysis. While an unmodified Firefox browser does not generate RSA keys in normal operation and is not affected, products built on top of it might be vulnerable. The severity was rated as moderate for Firefox and high for NSS servers (Mozilla Advisory, Ubuntu Notice).
The vulnerability requires local access and the ability to perform electromagnetic-based side channel attacks. The attack technique is similar to CVE-2018-0737 which was previously issued by OpenSSL for their library. The vulnerability is particularly concerning for server software where local access might be available to attackers (Mozilla Bugzilla).
The vulnerability was fixed in Firefox 78 and NSS 3.53.1. Various Linux distributions have released patches including Ubuntu (versions 20.04, 19.10, 18.04, 16.04, and 14.04), Debian (version 2:3.42.1-1+deb10u3), and Fedora (NSS 3.54.0). Users are advised to upgrade to these patched versions (Ubuntu Notice, Debian Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."