After a HelloRetryRequest has been sent, the client may negotiate a lower protocol that TLS 1.3, resulting in an invalid state transition in the TLS State Machine. If the client gets into this state, incoming Application Data records will be ignored. This vulnerability affects Firefox < 72.
https://bugzilla.mozilla.org/show_bug.cgi?id=1590001
https://usn.ubuntu.com/4234-1/
https://usn.ubuntu.com/4397-1/
Source: MITRE
Published: 2020-01-08
Updated: 2020-07-18
Type: CWE-287
Base Score: 4.3
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N
Impact Score: 2.9
Exploitability Score: 8.6
Severity: MEDIUM
Base Score: 6.5
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Impact Score: 3.6
Exploitability Score: 2.8
Severity: MEDIUM
OR
OR
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
ID | Name | Product | Family | Severity |
---|---|---|---|---|
147361 | NewStart CGSL CORE 5.04 / MAIN 5.04 : nss Multiple Vulnerabilities (NS-SA-2021-0019) | Nessus | NewStart CGSL Local Security Checks | critical |
147281 | NewStart CGSL MAIN 6.02 : nss Multiple Vulnerabilities (NS-SA-2021-0053) | Nessus | NewStart CGSL Local Security Checks | critical |
145878 | CentOS 8 : nss and nspr (CESA-2020:3280) | Nessus | CentOS Local Security Checks | critical |
142720 | Amazon Linux 2 : nspr (ALAS-2020-1559) | Nessus | Amazon Linux Local Security Checks | critical |
142600 | CentOS 7 : nss and nspr (CESA-2020:4076) | Nessus | CentOS Local Security Checks | critical |
141689 | Scientific Linux Security Update : nss and nspr on SL7.x x86_64 (20201001) | Nessus | Scientific Linux Local Security Checks | critical |
141312 | Oracle Linux 7 : nss / and / nspr (ELSA-2020-4076) | Nessus | Oracle Linux Local Security Checks | critical |
141059 | RHEL 7 : nss and nspr (RHSA-2020:4076) | Nessus | Red Hat Local Security Checks | critical |
139397 | Oracle Linux 8 : nspr / nss (ELSA-2020-3280) | Nessus | Oracle Linux Local Security Checks | medium |
139293 | RHEL 8 : nss and nspr (RHSA-2020:3280) | Nessus | Red Hat Local Security Checks | critical |
138646 | Debian DSA-4726-1 : nss - security update | Nessus | Debian Local Security Checks | critical |
137555 | Ubuntu 16.04 LTS / 18.04 LTS / 19.10 / 20.04 : NSS vulnerabilities (USN-4397-1) | Nessus | Ubuntu Local Security Checks | medium |
132854 | Ubuntu 16.04 LTS / 18.04 LTS / 19.04 / 19.10 : firefox vulnerabilities (USN-4234-1) | Nessus | Ubuntu Local Security Checks | medium |
132709 | Mozilla Firefox < 72.0 Multiple Vulnerabilities | Nessus | Windows | medium |
132708 | Mozilla Firefox < 72.0 Multiple Vulnerabilities | Nessus | MacOS X Local Security Checks | medium |