SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2016-0772

The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when StartTLS fails, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network…

MEDIUM 6.5EPSS 14.5%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 14.5%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.

Description

The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when StartTLS fails, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a "StartTLS stripping attack."

CVSS 3.0
6.5 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N
EPSS
14.52% probability · 96th percentile
CISA KEV
Not listed
Weakness
CWE-693
Affected
python/python
Source
secalert@redhat.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.