Impact
The vulnerability resides in Firefox’s Networking: HTTP component and allows a malicious actor to present a forged response or server identity to the browser. The flaw enables the attacker to masquerade as a legitimate web server, potentially intercepting sensitive data or delivering malicious content without the user’s awareness. This type of spoofing directly compromises authentication integrity and can lead to man‑in‑the‑middle attacks or phishing through authentic‑appearing HTTPS connections.
Affected Systems
Mozilla products, specifically Firefox and Firefox ESR, are affected. The issue is fixed in Firefox ESR 153.4 and Firefox 157, meaning any older build is vulnerable.
Risk and Exploitability
The CVSS score is not provided, and the EPSS is not available, so the precise magnitude of risk is unclear from the data. According to the KEV catalog, the vulnerability is not listed, indicating no publicly known exploitation at this time. Nevertheless, the flaw involves network traffic that could be abused by an attacker with network proximity or a compromised DNS entry. The attack vector is likely remote over HTTP/HTTPS, though exact exploitation steps are not detailed in the available information.
OpenCVE Enrichment