Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:24139
HistoryApr 10, 2020 - 12:47 a.m.

Man-in-the-middle

2020-04-1000:47:07
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13

EPSS

0

Percentile

5.1%

The Simple Protocol for Independent Computing Environments (SPICE) is vulnerable to Man-in-the-middle. A race condition was found in the way the SPICE Mozilla Firefox plug-in and the SPICE client communicated. A local attacker could use this flaw to trick the plug-in and the SPICE client into communicating over an attacker-controlled socket, possibly gaining access to authentication details, or resulting in a man-in-the-middle attack on the SPICE connection.

EPSS

0

Percentile

5.1%