CVE-2024-5690
Mozilla Firefox ≤ 127.0
Raw vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:NSummary
CVE-2024-5690 is a medium-severity Observable Discrepancy (CWE-203) vulnerability in Mozilla Firefox. Its CVSS base score is 4.3 (Medium).
Operationally, exploitation aligns with the MITRE ATT&CK technique Account Discovery (T1087); ranked in the top 49% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified map to IA-6 (Authentication Feedback) and SI-11 (Error Handling) — see the control section below for these in your framework.
Deeper analysis AI-assisted summary
Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.
CVE-2024-5690 is a timing-based information disclosure vulnerability stemming from observable discrepancies in how certain operations execute. It affects Firefox versions prior to 127, Firefox ESR versions prior to 115.12, and Thunderbird versions prior to 115.12, allowing an attacker to infer the presence of functional external protocol handlers on a target system through measurement of operation durations. The issue is tracked under CWE-203 and carries a CVSS 3.1 score of 4.3.
An unauthenticated remote attacker can exploit the flaw by serving malicious web content that triggers and times specific operations, requiring user interaction such as visiting a crafted page. Successful exploitation yields limited information about which external protocol handlers are active, potentially aiding further reconnaissance or targeted attacks without direct code execution or privilege escalation.
Mozilla security advisories MFSA2024-25 and MFSA2024-26, along with corresponding Debian LTS announcements, direct users to apply the fixed releases (Firefox 127, ESR 115.12, and Thunderbird 115.12) as the primary mitigation. The referenced Bugzilla entry provides additional technical detail on the root cause and resolution.
EPSS scores for this CVE have remained flat at 0.0588 with no material increase observed since disclosure.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2024-46862
Vulnerability Data
By monitoring the time certain operations take, an attacker could have guessed which external protocol handlers were functional on a user's system. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise Techniques
CVEs Like This One
Affected Assets
Mitigating Controls
Control response
—
—
- 1 hardening rule · 1 OS baseline
—
Mitigating Controls (NIST 800-53 r5) AI
Obscures authentication feedback so that success/failure differences are not observable to attackers.
Requires error messages to avoid revealing exploitable details, directly stopping observable response discrepancies.
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Secure SDLC practices directly prevent observable response discrepancies via consistent error handling and timing.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Accurate, synchronized timestamps reduce observable timing discrepancies that an attacker could exploit to infer sensitive information or distinguish between success and failure paths.