CVE-2020-6824 describes a low-severity vulnerability in Mozilla Firefox versions prior to 75. It allowed the browser's password generator to produce identical passwords across separate Private Browsing sessions for the same site, rather than unique ones. The attack requires local user interaction and has a low impact on confidentiality, with no integrity or availability impact. There is no evidence of active exploitation, and no public exploit code or Metasploit modules are available, though it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 75.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
< 75CPE match | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.