Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2020-15679

19
FAUCET Score

CVE-2020-15679 describes an OAuth session fixation vulnerability in Mozilla VPN's login flow, affecting iOS versions prior to 1.0.7 (929), Windows versions prior to 1.2.2, and Android versions prior to 1.1.0 (1360). An attacker could craft a malicious login URL and, if the victim and attacker share the same source IP, gain authenticated access to the victim's VPN session, allowing them to view session states and disconnect VPN connections. Rated 7.6 HIGH on the CVSS scale, this vulnerability requires user interaction (UI:R) and has a high impact on availability (A:H) with low impact on confidentiality and integrity. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.0.7_\(929\)CPE matchmatch criteria
cpe:2.3:a:mozilla:vpn:*:*:*:*:*:iphone_os:*:*
< 1.2.2CPE matchmatch criteria
cpe:2.3:a:mozilla:vpn:*:*:*:*:*:windows:*:*
>= 1.0.7, < 1.0.7_\(929\)CPE matchmatch criteria
cpe:2.3:a:mozilla:vpn:*:*:*:*:*:ipados:*:*
>= 1.1.0, < 1.1.0_\(1360\)CPE matchmatch criteria
cpe:2.3:a:mozilla:vpn:*:*:*:*:*:android:*:*

CVSS Data

CVSS version used by this source: 3.1

7.6HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
4.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.47%
Probability of exploitation in next 30 days
EPSS Percentile
38.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0047 is in the 40th percentile among its peer group of 14,848 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
mozillavendor investigatingvia nvd_reference
View patch

References

github.com / mozilla-mobile/guardian-vpn-android/commit/981c840276ef3aee98cf5d42993d484ee99b28d9
PatchThird Party Advisory
github.com / mozilla-mobile/guardian-vpn-ios/commit/4309f5c9bd2c15cdfd39ac173665fad3f2598b54
PatchThird Party Advisory
github.com / mozilla-services/guardian-vpn-windows/commit/ac6f562973a83f6758cd7ab7aa313e863047d41b
PatchThird Party Advisory
mozilla.org / security/advisories/mfsa2020-48
Vendor Advisory