Lucene search

K
cveMozillaCVE-2023-29534
HistoryJun 19, 2023 - 11:15 a.m.

CVE-2023-29534

2023-06-1911:15:09
mozilla
web.nvd.nist.gov
41
cve-2023-29534
firefox
focus
android
fullscreen notification
user confusion
spoofing attacks
nvd

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

AI Score

8.5

Confidence

High

EPSS

0.003

Percentile

70.3%

Different techniques existed to obscure the fullscreen notification in Firefox and Focus for Android. These could have led to potential user confusion and spoofing attacks.

This bug only affects Firefox and Focus for Android. Other versions of Firefox are unaffected. This vulnerability affects Firefox for Android < 112 and Focus for Android < 112.

Affected configurations

Nvd
Vulners
Node
mozillafirefoxRange<112.0android
OR
mozillafirefox_focusRange<112.0android
VendorProductVersionCPE
mozillafirefox*cpe:2.3:a:mozilla:firefox:*:*:*:*:*:android:*:*
mozillafirefox_focus*cpe:2.3:a:mozilla:firefox_focus:*:*:*:*:*:android:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Firefox for Android",
    "vendor": "Mozilla",
    "versions": [
      {
        "lessThan": "112",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Focus for Android",
    "vendor": "Mozilla",
    "versions": [
      {
        "lessThan": "112",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

AI Score

8.5

Confidence

High

EPSS

0.003

Percentile

70.3%