Impact
A denial-of-service vulnerability exists in the WebRTC Signaling component of Mozilla products. The flaw can cause the application to consume excessive resources or crash, rendering it unresponsive to legitimate users. It is identified by CWE-400 and CWE-770 and has a CVSS score of 7.5.
Affected Systems
Mozilla Firefox versions earlier than 149 and Firefox ESR earlier than 140.9, as well as Mozilla Thunderbird versions earlier than 149 and Thunderbird ESR earlier than 140.9, are affected by this flaw. Users running these releases risk interruption of WebRTC-enabled features.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, while the EPSS score of less than 1% suggests a low probability of exploitation. It is not included in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is remote and would require the receipt of a malicious WebRTC signaling message, which a user might encounter when visiting a compromised or malicious website.
OpenCVE Enrichment
Debian DLA
Debian DSA