CVE-2020-12413: Mozilla Firefox

Medium severity, CVSS 5.9. EPSS: 0.6% chance of exploitation in the next 30 days.

The Raccoon attack is a timing attack on DHE ciphersuites inherit in the TLS specification. To mitigate this vulnerability, Firefox disabled support for DHE ciphersuites.

Affected products

  • Mozilla Firefox: before 78.0 (fixed in 78.0)
  • Mozilla Firefox ESR: before 68.10.0 (fixed in 68.10.0)

Published 2023-02-16. Last modified 2026-06-17.