HIGH · 7.1

CVE-2016-1587

The Snapweb interface before version 0.21.2 was exposing controls to install or remove snap packages without controlling the identity of the user, nor the origin of the connection. An attacker could h...

Vulnerability Description

The Snapweb interface before version 0.21.2 was exposing controls to install or remove snap packages without controlling the identity of the user, nor the origin of the connection. An attacker could have used the controls to remotely add a valid, but malicious, snap package, from the Store, potentially using system resources without permission from the legitimate administrator of the system.

CVSS Score

7.1

HIGH

CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality
LOW
Integrity
LOW
Availability
LOW

Affected Products

VendorProductVersions
SnapwebSnapweb< 0.21.2

Related Weaknesses (CWE)

References

FAQ

What is CVE-2016-1587?

CVE-2016-1587 is a vulnerability with a CVSS score of 7.1 (HIGH). The Snapweb interface before version 0.21.2 was exposing controls to install or remove snap packages without controlling the identity of the user, nor the origin of the connection. An attacker could h...

How severe is CVE-2016-1587?

CVE-2016-1587 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2016-1587?

Check the references section above for vendor advisories and patch information. Affected products include: Snapweb Snapweb.