Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2020-13962

20
FAUCET Score

CVE-2020-13962 describes a denial-of-service vulnerability in Qt versions 5.12.2 through 5.14.2, affecting products like Mumble 1.3.0 and others utilizing QSslSocket. The flaw stems from improper handling of OpenSSL's error queue, leading to unrelated TLS sessions being disconnected when any handshake fails. With a CVSS score of 7.5 (High), this network-exploitable vulnerability has a high impact on availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
1.3.0CPE matchmatch criteria
cpe:2.3:a:mumble:mumble:1.3.0:-:*:*:*:*:*:*
>= 5.12.2, < 5.12.9CPE matchmatch criteria
cpe:2.3:a:qt:qt:*:*:*:*:*:*:*:*
>= 5.13.0, <= 5.13.2CPE matchmatch criteria
cpe:2.3:a:qt:qt:*:*:*:*:*:*:*:*
>= 5.14.0, <= 5.14.2CPE matchmatch criteria
cpe:2.3:a:qt:qt:*:*:*:*:*:*:*:*
31CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
3.01%
Probability of exploitation in next 30 days
EPSS Percentile
86.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0301 is in the 75th percentile among its peer group of 51,485 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (13)

github_advisorypatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: 16857-16823Fixed in: 5.12.11-3
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 5.12.11-3
microsoftpatch availablevia msrc
Product: cbl2 qt5-qtsvg 5.12.11-3 on CBL Mariner 2.0Fixed in: 5.12.11-3
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 5.12.11-3
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: qt5-qtbase-0:5.12.5-6.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: qt5-qttools-0:5.12.5-2.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: qt5-qtwebsockets-0:5.12.5-2.el8
View patch
ubuntupatch availablevia ubuntu_usn
Product: qtbase-opensource-src (noble)Fixed in: 5.15.13+dfsg-1ubuntu1+esm1
ubuntupatch availablevia ubuntu_usn
Product: qtbase-opensource-src (bionic)Fixed in: 5.9.5+dfsg-0ubuntu2.6+esm2
ubuntupatch availablevia ubuntu_usn
Product: qtbase-opensource-src (xenial)Fixed in: 5.5.1+dfsg-16ubuntu7.7+esm2
ubuntupatch availablevia ubuntu_usn
Product: qtbase-opensource-src (focal)Fixed in: 5.12.8+dfsg-0ubuntu2.1+esm3
ubuntupatch availablevia ubuntu_usn
Product: qtbase-opensource-src (jammy)Fixed in: 5.15.3+dfsg-2ubuntu0.2+esm3

Vendor Advisories (4)

ubuntuUSN-8076-1

Qt vulnerabilities

Mar 5, 2026
microsoft2021-Dec/CVE-2020-13962

CVE-2020-13962

Dec 14, 2021
microsoft2020-Jun/CVE-2020-13962Important

Qt 5.12.2 through 5.14.2 as used in unofficial builds of Mumble 1.3.0 and other products mishandles OpenSSL's error queue which can cause a denial of service to QSslSocket users. Because errors leak in unrelated TLS sessions an unrelated session may be disconnected when any handshake fails. (Mumble 1.3.1 is not affected regardless of the Qt version.)

Jun 9, 2020
redhatCVE-2020-13962Moderate

qt5: incorrectly calls SSL_shutdown() in OpenSSL mid-handshake causing denial of service in TLS applications

Jun 9, 2020

References

lists.opensuse.org / opensuse-security-announce/2020-09/msg00004.html
Mailing ListThird Party Advisory
bugreports.qt.io / browse/QTBUG-83450
Issue TrackingVendor Advisory
github.com / mumble-voip/mumble/issues/3679
ExploitIssue TrackingPatchThird Party Advisory
github.com / mumble-voip/mumble/pull/4032
PatchThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/4X6EDPIIAQPVP2CHL2CHDHJ25EECA7UE
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/UQJDBZUYMMF4R5QQKD2HTIKQU2NSKO63
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/V3IZY7LKJ6NAXQDFYFR4S7L5BBHYK53K
security.gentoo.org / glsa/202007-18
Third Party Advisory