7.5

CVE-2016-1232

The mod_dialback module in Prosody before 0.9.9 does not properly generate random values for the secret token for server-to-server dialback authentication, which makes it easier for attackers to spoof servers via a brute force attack.

Data is provided by the National Vulnerability Database (NVD)
ProsodyProsody Version <= 0.9.8
ProsodyProsody Version0.9.0
ProsodyProsody Version0.9.1
ProsodyProsody Version0.9.2
ProsodyProsody Version0.9.3
ProsodyProsody Version0.9.4
ProsodyProsody Version0.9.5
ProsodyProsody Version0.9.6
ProsodyProsody Version0.9.7
FedoraprojectFedora Version22
FedoraprojectFedora Version23
DebianDebian Linux Version7.0
DebianDebian Linux Version8.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.71% 0.712
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N