8.1
CVE-2016-10673
- EPSS 0.16%
- Veröffentlicht 04.06.2018 16:29:01
- Zuletzt bearbeitet 21.11.2024 02:44:29
- Quelle support@hackerone.com
- CVE-Watchlists
- Unerledigt
ipip-coffee queries geolocation information from IP ipip-coffee downloads geolocation resources over HTTP, which leaves it vulnerable to MITM attacks. This could impact the integrity and availability of the data being used to make geolocation decisions by an application.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ipip ≫ Ipip-coffee SwPlatformnode.js Version <= 1.0.9
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.16% | 0.38 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.1 | 2.2 | 5.9 |
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
CWE-311 Missing Encryption of Sensitive Data
The product does not encrypt sensitive or critical information before storage or transmission.