CVE-2014-1568 describes a signature malleability vulnerability in Mozilla Network Security Services (NSS) versions before 3.16.2.1, 3.16.5, and 3.17.1, impacting various Mozilla products, Google Chrome, and Chrome OS. This flaw stems from improper ASN.1 parsing in X.509 certificates, allowing remote attackers to spoof RSA signatures with crafted certificates. With a CVSS score of 7.5 (high) and an EPSS score indicating significant exploitability, this vulnerability presents a critical risk due to its network-based attack vector, low attack complexity, and potential for partial compromise of confidentiality, integrity, and availability. While no public exploit code (Metasploit, Nuclei, ExploitDB) is available and it's not in CISA's KEV catalog, the vulnerability has garnered community discussion and media coverage, suggesting awareness among threat actors.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 37.0.2062.120CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
<= 32.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
31.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:31.0:*:*:*:*:*:*:* | ||
31.1.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:31.1.0:*:*:*:*:*:*:* | ||
32.0.1CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:32.0.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.