Vulnerability Description
ipip-coffee queries geolocation information from IP ipip-coffee downloads geolocation resources over HTTP, which leaves it vulnerable to MITM attacks. This could impact the integrity and availability of the data being used to make geolocation decisions by an application.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ipip | Ipip-Coffee | <= 1.0.9 |
Related Weaknesses (CWE)
References
- https://nodesecurity.io/advisories/279Third Party Advisory
- https://nodesecurity.io/advisories/279Third Party Advisory
FAQ
What is CVE-2016-10673?
CVE-2016-10673 is a vulnerability with a CVSS score of 8.1 (HIGH). ipip-coffee queries geolocation information from IP ipip-coffee downloads geolocation resources over HTTP, which leaves it vulnerable to MITM attacks. This could impact the integrity and availability ...
How severe is CVE-2016-10673?
CVE-2016-10673 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-10673?
Check the references section above for vendor advisories and patch information. Affected products include: Ipip Ipip-Coffee.