CVE-2019-17006
9.8
CRITICAL · CVSS 3.1 · EPSS 3.6% (pctl 89)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the library did not perform a sanity check on the inputs it could result in a crash due to a buffer overflow.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.56% — more likely to be exploited than 89% of all CVEs |
| Weakness | CWE-20 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2020-10-22 |
| Last modified | 2026-06-17 |
Affected (21)
| Vendor | Product |
|---|---|
| mozilla | network security services |
| netapp | hci compute node |
| netapp | hci management node |
| netapp | hci storage node |
| netapp | solidfire |
| siemens | ruggedcom rox mx5000 |
| siemens | ruggedcom rox mx5000 firmware |
| siemens | ruggedcom rox rx1400 |
| siemens | ruggedcom rox rx1400 firmware |
| siemens | ruggedcom rox rx1500 |
| siemens | ruggedcom rox rx1500 firmware |
| siemens | ruggedcom rox rx1501 |
| siemens | ruggedcom rox rx1501 firmware |
| siemens | ruggedcom rox rx1510 |
| siemens | ruggedcom rox rx1510 firmware |
| siemens | ruggedcom rox rx1511 |
| siemens | ruggedcom rox rx1511 firmware |
| siemens | ruggedcom rox rx1512 |
| siemens | ruggedcom rox rx1512 firmware |
| siemens | ruggedcom rox rx5000 |
| siemens | ruggedcom rox rx5000 firmware |
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=1539788
- https://cert-portal.siemens.com/productcert/pdf/ssa-379803.pdf
- https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.46_release_notes
- https://security.netapp.com/advisory/ntap-20210129-0001/
- https://us-cert.cisa.gov/ics/advisories/icsa-21-040-04
- https://bugzilla.mozilla.org/show_bug.cgi?id=1539788
- https://cert-portal.siemens.com/productcert/pdf/ssa-379803.pdf
- https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.46_release_notes
- https://security.netapp.com/advisory/ntap-20210129-0001/
- https://us-cert.cisa.gov/ics/advisories/icsa-21-040-04
→ the Explorer · watch your stack · NVD