CVE-2013-1620

The TLS implementation in Mozilla Network Security Services (NSS) does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169.

Published: 2013-02-08 Last update: 2026-04-29 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2013-1620 is rated Moderate Risk (43.5/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 0.85%). Mandatory action: Review affected assets and schedule remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2013-1620

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-04-23 0.81% 0.85% +0.05%
2 2025-12-28 0.59% 0.81% +0.21%
3 2025-12-27 0.59%

Full EPSS history (16 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2013-1620

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
4.3 2.0 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:M)
Exploitation needs some favorable conditions, but not exceptional ones.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:P)
Partial confidentiality impact.
Integrity impact (I:N)
No integrity impact.
Availability impact (A:N)
No availability impact.
8.6 2.9 [email protected]

Weakness enumeration for CVE-2013-1620

OS Trackers for CVE-2013-1620

vendor priority summary link
debian low CVE-2013-1620 low priority: Debian including 1 source packages (nss), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. https://security-tracker.debian.org/tracker/CVE-2013-1620
gentoo normal CVE-2013-1620: 1 GLSA(s) (201406-19), 1 atom(s) (dev-libs/nss); latest impact normal. https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2013-1620
redhat medium https://access.redhat.com/security/cve/CVE-2013-1620
suse medium CVE-2013-1620 severity moderate: SUSE including 167 source package names (libfreebl3-3.101.2-slfo.1.1_1.6, libfreebl3-3.112-160000.2.2, …), 405 product×package rows across 48 product lines (SUSE CaaS Platform 4.0, SUSE Enterprise Storage 6, … (48 product lines)): Fixed 242, Known Not Affected 163. https://www.suse.com/security/cve/CVE-2013-1620/
ubuntu medium CVE-2013-1620 medium priority: Ubuntu including 1 source packages (nss), 6 status rows across 6 suites (hardy, lucid, oneiric, precise, quantal, upstream): released 5, ignored 1. https://ubuntu.com/security/CVE-2013-1620

Affected software / configurations for CVE-2013-1620

Vendor Product Version Raw CPE
mozilla network_security_services < 3.14.3 cpe:2.3:a:mozilla:network_security_services:*:*:*:*:*:*:*:*
canonical ubuntu_linux 10.04 cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:-:*:*:*
canonical ubuntu_linux 11.10 cpe:2.3:o:canonical:ubuntu_linux:11.10:*:*:*:*:*:*:*
canonical ubuntu_linux 12.04 cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-:*:*:*
canonical ubuntu_linux 12.10 cpe:2.3:o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*
oracle enterprise_manager_ops_center 11.1 cpe:2.3:a:oracle:enterprise_manager_ops_center:11.1:*:*:*:*:*:*:*
oracle enterprise_manager_ops_center 12.1 cpe:2.3:a:oracle:enterprise_manager_ops_center:12.1:*:*:*:*:*:*:*
oracle enterprise_manager_ops_center 12.2 cpe:2.3:a:oracle:enterprise_manager_ops_center:12.2:*:*:*:*:*:*:*
oracle glassfish_communications_server 2.0 cpe:2.3:a:oracle:glassfish_communications_server:2.0:*:*:*:*:*:*:*
oracle glassfish_server 2.1.1 cpe:2.3:a:oracle:glassfish_server:2.1.1:*:*:*:*:*:*:*
oracle iplanet_web_proxy_server 4.0 cpe:2.3:a:oracle:iplanet_web_proxy_server:4.0:*:*:*:*:*:*:*
oracle iplanet_web_server 6.1 cpe:2.3:a:oracle:iplanet_web_server:6.1:*:*:*:*:*:*:*
oracle iplanet_web_server 7.0 cpe:2.3:a:oracle:iplanet_web_server:7.0:*:*:*:*:*:*:*
oracle opensso 3.0-03 cpe:2.3:a:oracle:opensso:3.0-03:*:*:*:*:*:*:*
oracle traffic_director 11.1.1.6.0 cpe:2.3:a:oracle:traffic_director:11.1.1.6.0:*:*:*:*:*:*:*
oracle traffic_director 11.1.1.7.0 cpe:2.3:a:oracle:traffic_director:11.1.1.7.0:*:*:*:*:*:*:*
oracle vm_server 3.2 cpe:2.3:a:oracle:vm_server:3.2:*:*:*:*:*:x86:*
redhat enterprise_linux_desktop 5.0 cpe:2.3:o:redhat:enterprise_linux_desktop:5.0:*:*:*:*:*:*:*
redhat enterprise_linux_desktop 6.0 cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
redhat enterprise_linux_eus 5.9 cpe:2.3:o:redhat:enterprise_linux_eus:5.9:*:*:*:*:*:*:*
redhat enterprise_linux_server 5.0 cpe:2.3:o:redhat:enterprise_linux_server:5.0:*:*:*:*:*:*:*
redhat enterprise_linux_server 6.0 cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
redhat enterprise_linux_server_aus 5.9 cpe:2.3:o:redhat:enterprise_linux_server_aus:5.9:*:*:*:*:*:*:*
redhat enterprise_linux_workstation 5.0 cpe:2.3:o:redhat:enterprise_linux_workstation:5.0:*:*:*:*:*:*:*
redhat enterprise_linux_workstation 6.0 cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*

References for CVE-2013-1620

URL Tags
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10761 Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00009.html Broken Link
http://lists.opensuse.org/opensuse-security-announce/2013-04/msg00010.html Broken Link
http://openwall.com/lists/oss-security/2013/02/05/24 Mailing List Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2013-1135.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2013-1144.html Third Party Advisory
http://seclists.org/fulldisclosure/2014/Dec/23 Mailing List Third Party Advisory
http://security.gentoo.org/glsa/glsa-201406-19.xml Third Party Advisory
http://www.isg.rhul.ac.uk/tls/TLStiming.pdf Technical Description Third Party Advisory
http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html Third Party Advisory
http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html Third Party Advisory
http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html Third Party Advisory
http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html Third Party Advisory
http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html Third Party Advisory
http://www.securityfocus.com/archive/1/534161/100/0/threaded Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/57777 Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/64758 Third Party Advisory VDB Entry
http://www.ubuntu.com/usn/USN-1763-1 Third Party Advisory
http://www.vmware.com/security/advisories/VMSA-2014-0012.html Third Party Advisory
cvelogic Threat Intelligence