Cyber Resilience

CVE-2024-5690

Mozilla Firefox ≤ 127.0

Published
11 June 2024
Modified
26 March 2025
Patch / advisory
CVSS Score v3.1 4.3
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
EPSS Score 0.0074 51th percentile
Risk Priority 44 floored blend · peak EPSS

Summary

CVE-2024-5690 is a medium-severity Observable Discrepancy (CWE-203) vulnerability in Mozilla Firefox. Its CVSS base score is 4.3 (Medium).

Operationally, exploitation aligns with the MITRE ATT&CK technique Account Discovery (T1087); ranked in the top 49% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.

The strongest mitigations our analysis identified map to IA-6 (Authentication Feedback) and SI-11 (Error Handling) — see the control section below for these in your framework.

Deeper analysis AI-assisted summary

Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.

CVE-2024-5690 is a timing-based information disclosure vulnerability stemming from observable discrepancies in how certain operations execute. It affects Firefox versions prior to 127, Firefox ESR versions prior to 115.12, and Thunderbird versions prior to 115.12, allowing an attacker to infer the presence of functional external protocol handlers on a target system through measurement of operation durations. The issue is tracked under CWE-203 and carries a CVSS 3.1 score of 4.3.

An unauthenticated remote attacker can exploit the flaw by serving malicious web content that triggers and times specific operations, requiring user interaction such as visiting a crafted page. Successful exploitation yields limited information about which external protocol handlers are active, potentially aiding further reconnaissance or targeted attacks without direct code execution or privilege escalation.

Mozilla security advisories MFSA2024-25 and MFSA2024-26, along with corresponding Debian LTS announcements, direct users to apply the fixed releases (Firefox 127, ESR 115.12, and Thunderbird 115.12) as the primary mitigation. The referenced Bugzilla entry provides additional technical detail on the root cause and resolution.

EPSS scores for this CVE have remained flat at 0.0588 with no material increase observed since disclosure.

EU & UK References

Vulnerability Data

By monitoring the time certain operations take, an attacker could have guessed which external protocol handlers were functional on a user's system. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.

CWE(s)

Related Threats

MITRE ATT&CK Enterprise Techniques

T1087 Account Discovery Discovery
Adversaries may attempt to get a listing of valid accounts, usernames, or email addresses on a system or within a compromised environment.
T1110 Brute Force Credential Access
Adversaries may use brute force techniques to gain access to accounts when passwords are unknown or when password hashes are obtained.
T1595 Active Scanning Reconnaissance
Adversaries may execute active reconnaissance scans to gather information that can be used during targeting.
Derived from this CVE’s CWE(s) via the direct CWE→ATT&CK cross-walk.

CVEs Like This One

CVE-2023-5388Same product: Debian Debian Linux
CVE-2024-9398Same product: Mozilla Firefox
CVE-2023-25728Same product: Mozilla Firefox
CVE-2024-10463Same product: Mozilla Firefox
CVE-2024-0751Same product: Debian Debian Linux
CVE-2024-0750Same product: Debian Debian Linux
CVE-2024-0755Same product: Debian Debian Linux
CVE-2023-37208Same product: Debian Debian Linux
CVE-2023-6212Same product: Debian Debian Linux
CVE-2024-0742Same product: Debian Debian Linux

Affected Assets

mozilla
firefox
≤ 127.0
mozilla
firefox esr
≤ 115.12
mozilla
thunderbird
≤ 115.12
debian
debian linux
10.0

Mitigating Controls

Control response

Prevent
Stop it (NIST 800-53)

Detect
Catch it (NIST detect / respond)

Harden
Shrink the surface (DISA STIG)
  • 1 hardening rule · 1 OS baseline
Validate
Prove the fix (OWASP ASVS)

Mitigating Controls (NIST 800-53 r5) AI

Obscures authentication feedback so that success/failure differences are not observable to attackers.

Requires error messages to avoid revealing exploitable details, directly stopping observable response discrepancies.

Mitigating Controls (NIST CSF 2.0) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.

PR.PS-06 mostly match
prevents

Secure SDLC practices directly prevent observable response discrepancies via consistent error handling and timing.

Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.

none

Accurate, synchronized timestamps reduce observable timing discrepancies that an attacker could exploit to infer sensitive information or distinguish between success and failure paths.

References