CVE-2019-11727 describes a vulnerability in Network Security Services (NSS) that allows a server to force the use of insecure PKCS#1 v1.5 signatures for CertificateVerify in TLS 1.3, which is not compliant with TLS 1.3 specifications. This flaw primarily impacts Firefox versions prior to 68. Rated as Medium severity (CVSS 5.3), it carries a low impact on integrity (I:L) and requires no user interaction or privileges, with a network attack vector. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 68CPE match | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
< 68.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.