CVE-2020-15679 describes an OAuth session fixation vulnerability in Mozilla VPN's login flow, affecting iOS versions prior to 1.0.7 (929), Windows versions prior to 1.2.2, and Android versions prior to 1.1.0 (1360). An attacker could craft a malicious login URL and, if the victim and attacker share the same source IP, gain authenticated access to the victim's VPN session, allowing them to view session states and disconnect VPN connections. Rated 7.6 HIGH on the CVSS scale, this vulnerability requires user interaction (UI:R) and has a high impact on availability (A:H) with low impact on confidentiality and integrity. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.7_\(929\)CPE matchmatch criteria | cpe:2.3:a:mozilla:vpn:*:*:*:*:*:iphone_os:*:* | ||
< 1.2.2CPE matchmatch criteria | cpe:2.3:a:mozilla:vpn:*:*:*:*:*:windows:*:* | ||
>= 1.0.7, < 1.0.7_\(929\)CPE matchmatch criteria | cpe:2.3:a:mozilla:vpn:*:*:*:*:*:ipados:*:* | ||
>= 1.1.0, < 1.1.0_\(1360\)CPE matchmatch criteria | cpe:2.3:a:mozilla:vpn:*:*:*:*:*:android:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.