PT-2022-8577 · Mozilla · Vpn

Published

2022-12-22

·

Updated

2022-12-29

·

CVE-2020-15679

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions Mozilla VPN iOS versions 1.0.7 and earlier Mozilla VPN Windows versions prior to 1.2.2 Mozilla VPN Android versions 1.1.0 and earlier
Description An issue existed in the VPN login flow, where an attacker could craft a custom login URL and convince a VPN user to login via that URL, obtaining authenticated access as that user. This issue is limited to cases where the attacker and victim share the same source IP and could allow the ability to view session states and disconnect VPN sessions.
Recommendations For Mozilla VPN iOS versions 1.0.7 and earlier, update to a version later than 1.0.7. For Mozilla VPN Windows versions prior to 1.2.2, update to version 1.2.2 or later. For Mozilla VPN Android versions 1.1.0 and earlier, update to a version later than 1.1.0.

Fix

Session Fixation

Weakness Enumeration

Related Identifiers

CVE-2020-15679

Affected Products

Vpn