6.5 CVE-2023-4580

 

Push notifications stored on disk in private browsing mode were not being encrypted potentially allowing the leak of sensitive information. This vulnerability affects Firefox < 117, Firefox ESR < 115.2, and Thunderbird < 115.2.
https://nvd.nist.gov/vuln/detail/CVE-2023-4580

Categories

CWE-311 : Missing Encryption of Sensitive Data
The lack of proper data encryption passes up the guarantees of confidentiality, integrity, and accountability that properly implemented encryption conveys.

References


 

CPE

cpe start end
Configuration 1
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* < 115.2
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* < 117.0
cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:* < 115.2


REMEDIATION




EXPLOITS


Exploit-db.com

id description date
No known exploits

Other (github, ...)

Url
No known exploits


CAPEC


Common Attack Pattern Enumerations and Classifications

id description severity
157 Sniffing Attacks
Medium
158 Sniffing Network Traffic
Medium
204 Lifting Sensitive Data Embedded in Cache
Medium
31 Accessing/Intercepting/Modifying HTTP Cookies
High
37 Retrieve Embedded Sensitive Data
Very High
383 Harvesting Information via API Event Monitoring
Low
384 Application API Message Manipulation via Man-in-the-Middle
Low
385 Transaction or Event Tampering via Application API Manipulation
Medium
386 Application API Navigation Remapping
Medium
387 Navigation Remapping To Propagate Malicious Content
Medium
388 Application API Button Hijacking
Medium
477 Signature Spoofing by Mixing Signed and Unsigned Content
High
609 Cellular Traffic Intercept
Low
65 Sniff Application Code
High


MITRE


Techniques

id description
T1005 Data from Local System
T1040 Network Sniffing
T1056.004 Input Capture: Credential API Hooking
T1111 Multi-Factor Authentication Interception
T1539 Steal Web Session Cookie
T1552.004 Unsecured Credentials: Private Keys
© 2022 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.

Mitigations

id description
T1005 Data loss prevention can restrict access to sensitive data and detect sensitive data that is unencrypted.
T1040 In cloud environments, ensure that users are not granted permissions to create or modify traffic mirrors unless this is explicitly required.
T1111 Remove smart cards when not in use.
T1539 Train users to identify aspects of phishing attempts where they're asked to enter credentials into a site that has the incorrect domain for the application they are logging into.
T1552.004 Ensure permissions are properly set on folders containing sensitive private keys to prevent unintended access.
© 2022 The MITRE Corporation. Esta obra se reproduce y distribuye con el permiso de The MITRE Corporation.