CVE-2020-6829 describes a side-channel vulnerability in Firefox and Firefox for Android versions prior to 80, where the wNAF point multiplication algorithm used during EC scalar point multiplication leaked partial nonce information. This allowed for potential private key computation through electromagnetic trace analysis of signature generations. The vulnerability has a CVSS score of 5.3 (Medium), indicating a network-based attack with low complexity, resulting in a low impact on confidentiality. There is no evidence of active exploitation, public exploit code, or Metasploit/Nuclei modules, though it has received limited community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 80.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:-:*:* | ||
< 80.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:android:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.