Back to search
CVE-2020-12401
Published: Oct 8, 2020
Modified: Aug 4, 2024
PUBLISHED
Description
During ECDSA signature generation, padding applied in the nonce designed to ensure constant-time scalar multiplication was removed, resulting in variable-time execution dependent on secret data. This vulnerability affects Firefox < 80 and Firefox for Android < 80.
| Vendor | Product | Versions |
|---|---|---|
Mozilla | Firefox | affected unspecified - < 80 |
Mozilla | Firefox for Android | affected unspecified - < 80 |
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now