CVE-2016-5672
Intel Crosswalk before 19.49.514.5, 20.x before 20.50.533.11, 21.x before 21.51.546.0, and 22.x before 22.51.549.0 interprets a user's acceptance of one invalid X.509 certificate to mean that all invalid X.509 certificates should be accepted without…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.74%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Intel Crosswalk before 19.49.514.5, 20.x before 20.50.533.11, 21.x before 21.51.546.0, and 22.x before 22.51.549.0 interprets a user's acceptance of one invalid X.509 certificate to mean that all invalid X.509 certificates should be accepted without prompting, which makes it easier for man-in-the-middle attackers to spoof SSL servers and obtain sensitive information via a crafted certificate.
- CVSS 3.0
- 8.1 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
- EPSS
- 1.74% probability · 76th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20, CWE-310
- Affected
- intel/crosswalk
- Source
- cret@cert.org
References
- http://packetstormsecurity.com/files/138107/Intel-Crosswalk-Project-Man-In-The-Middle.htmlThird Party Advisory, VDB Entry
- http://www.kb.cert.org/vuls/id/217871Third Party Advisory, US Government Resource
- http://www.securityfocus.com/archive/1/539051/100/0/threaded
- http://www.securityfocus.com/bid/92199Third Party Advisory, VDB Entry
- https://blogs.intel.com/evangelists/2016/07/28/crosswalk-security-vulnerability/Vendor Advisory
- https://crosswalk-project.org/jira/browse/XWALK-6986Permissions Required, Technical Description
- https://lists.crosswalk-project.org/pipermail/crosswalk-help/2016-July/002167.htmlVendor Advisory
- https://wwws.nightwatchcybersecurity.com/2016/07/29/advisory-intel-crosswalk-ssl-prompt-issueThird Party Advisory
- http://packetstormsecurity.com/files/138107/Intel-Crosswalk-Project-Man-In-The-Middle.htmlThird Party Advisory, VDB Entry
- http://www.kb.cert.org/vuls/id/217871Third Party Advisory, US Government Resource
- http://www.securityfocus.com/archive/1/539051/100/0/threaded
- http://www.securityfocus.com/bid/92199Third Party Advisory, VDB Entry
- https://blogs.intel.com/evangelists/2016/07/28/crosswalk-security-vulnerability/Vendor Advisory
- https://crosswalk-project.org/jira/browse/XWALK-6986Permissions Required, Technical Description
- https://lists.crosswalk-project.org/pipermail/crosswalk-help/2016-July/002167.htmlVendor Advisory
- https://wwws.nightwatchcybersecurity.com/2016/07/29/advisory-intel-crosswalk-ssl-prompt-issueThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.