CVE Vulnerabilities

CVE-2021-23982

Inadequate Encryption Strength

Published: Mar 31, 2021 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
6.1 MODERATE
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Using techniques that built on the slipstream research, a malicious webpage could have scanned both an internal networks hosts as well as services running on the users local machine utilizing WebRTC connections. This vulnerability affects Firefox ESR < 78.9, Firefox < 87, and Thunderbird < 78.9.

Weakness

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

Affected Software

NameVendorStart VersionEnd Version
FirefoxMozilla*87.0 (excluding)
Firefox_esrMozilla*78.9 (excluding)
ThunderbirdMozilla*78.9 (excluding)
Red Hat Enterprise Linux 7RedHatfirefox-0:78.9.0-1.el7_9*
Red Hat Enterprise Linux 7RedHatthunderbird-0:78.9.0-3.el7_9*
Red Hat Enterprise Linux 8RedHatfirefox-0:78.9.0-1.el8_3*
Red Hat Enterprise Linux 8RedHatthunderbird-0:78.9.0-3.el8_3*
Red Hat Enterprise Linux 8.1 Extended Update SupportRedHatfirefox-0:78.9.0-1.el8_1*
Red Hat Enterprise Linux 8.1 Extended Update SupportRedHatthunderbird-0:78.9.0-3.el8_1*
Red Hat Enterprise Linux 8.2 Extended Update SupportRedHatfirefox-0:78.9.0-1.el8_2*
Red Hat Enterprise Linux 8.2 Extended Update SupportRedHatthunderbird-0:78.9.0-3.el8_2*
FirefoxUbuntubionic*
FirefoxUbuntudevel*
FirefoxUbuntufocal*
FirefoxUbuntugroovy*
FirefoxUbuntuhirsute*
FirefoxUbuntuimpish*
FirefoxUbuntujammy*
FirefoxUbuntukinetic*
FirefoxUbuntulunar*
FirefoxUbuntumantic*
FirefoxUbuntunoble*
FirefoxUbuntutrusty*
FirefoxUbuntuupstream*
FirefoxUbuntuxenial*
Mozjs38Ubuntubionic*
Mozjs38Ubuntuesm-apps/bionic*
Mozjs38Ubuntuupstream*
Mozjs52Ubuntubionic*
Mozjs52Ubuntuesm-apps/focal*
Mozjs52Ubuntuesm-infra/bionic*
Mozjs52Ubuntufocal*
Mozjs52Ubuntugroovy*
Mozjs52Ubuntuupstream*
Mozjs60Ubuntuupstream*
Mozjs68Ubuntuesm-infra/focal*
Mozjs68Ubuntufocal*
Mozjs68Ubuntugroovy*
Mozjs68Ubuntuupstream*
Mozjs78Ubuntuesm-apps/jammy*
Mozjs78Ubuntugroovy*
Mozjs78Ubuntuhirsute*
Mozjs78Ubuntuimpish*
Mozjs78Ubuntujammy*
Mozjs78Ubuntukinetic*
Mozjs78Ubuntulunar*
Mozjs78Ubuntuupstream*
ThunderbirdUbuntubionic*
ThunderbirdUbuntudevel*
ThunderbirdUbuntufocal*
ThunderbirdUbuntugroovy*
ThunderbirdUbuntuhirsute*
ThunderbirdUbuntuimpish*
ThunderbirdUbuntujammy*
ThunderbirdUbuntukinetic*
ThunderbirdUbuntulunar*
ThunderbirdUbuntumantic*
ThunderbirdUbuntunoble*
ThunderbirdUbuntutrusty*
ThunderbirdUbuntuupstream*
ThunderbirdUbuntuxenial*

Potential Mitigations

References