#VU15735 Man-in-the-middle attack in Mozilla NSS - CVE-2018-12384
Published: November 6, 2018
Mozilla NSS
Mozilla
Description
The vulnerability allows a remote attacker to conduct man-in-the-middle attack on the target system.
The weakness exists due to ServerHello.random is all zero when handling a v2-compatible ClientHello. A remote attacker can use man-in-the-middle techniques to conduct passive replay attack and obtain potentially sensitive information.