Lucene search

K
cvelistMitreCVELIST:CVE-2016-10027
HistoryJan 12, 2017 - 11:00 p.m.

CVE-2016-10027

2017-01-1223:00:00
mitre
www.cve.org
7

AI Score

5.8

Confidence

High

EPSS

0.002

Percentile

59.9%

Race condition in the XMPP library in Smack before 4.1.9, when the SecurityMode.required TLS setting has been set, allows man-in-the-middle attackers to bypass TLS protections and trigger use of cleartext for client authentication by stripping the “starttls” feature from a server response.

AI Score

5.8

Confidence

High

EPSS

0.002

Percentile

59.9%