Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:3164
HistoryDec 21, 2016 - 3:54 a.m.

Man In The Middle (MitM)

2016-12-2103:54:53
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10

EPSS

0.002

Percentile

59.9%

Smack XMPP library is vulnerable to man-in-the-middle (MitM) attacks. This is because the security of the TLS connection is not always enforced, making it vulnerable to MitM. By stripping the “starttls” feature from the server response with a man-in-the-middle tool, an attacker can force the client to authenticate in clear text even if the “SecurityMode.required” TLS setting has been set. Note this is a race condition issue, so the attack works after a few tries.

EPSS

0.002

Percentile

59.9%