CVE-2025-6433
🟠 Łataj w tym tygodniu
Naruszenie specyfikacji WebAuthn w Firefox i Thunderbird umożliwia nieautoryzowane wyzwania WebAuthn.
CVSS
9.8
EPSS
0.3%
Exploit
none
Vendor
mozilla
Opis źródłowy (NVD)
If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was able to provide a WebAuthn challenge that the user would be prompted to complete. This is in violation of the WebAuthN spec which requires "a secure transport established without errors". This vulnerability was fixed in Firefox 140 and Thunderbird 140.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 9.8 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.3% |
| Opublikowano (NVD) | 2025-06-24 13:15:24 UTC |
| Ostatnia modyfikacja (NVD) | 2026-09-30 18:10:00 UTC |
Referencje