CVE Vulnerabilities

CVE-2021-23982

Inadequate Encryption Strength

Published: Mar 31, 2021 | Modified: Aug 06, 2021
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Using techniques that built on the slipstream research, a malicious webpage could have scanned both an internal networks hosts as well as services running on the users local machine utilizing WebRTC connections. This vulnerability affects Firefox ESR < 78.9, Firefox < 87, and Thunderbird < 78.9.

Weakness

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

Affected Software

Name Vendor Start Version End Version
Firefox Mozilla * 87.0 (excluding)
Firefox_esr Mozilla * 78.9 (excluding)
Thunderbird Mozilla * 78.9 (excluding)

Potential Mitigations

References