7.5
CVSSv3

CVE-2016-1232

Published: 12/01/2016 Updated: 09/06/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The mod_dialback module in Prosody prior to 0.9.9 does not properly generate random values for the secret token for server-to-server dialback authentication, which makes it easier for malicious users to spoof servers via a brute force attack.

Vulnerable Product Search on Vulmon Subscribe to Product

prosody prosody 0.9.6

prosody prosody 0.9.4

prosody prosody 0.9.3

prosody prosody 0.9.2

prosody prosody 0.9.1

prosody prosody 0.9.0

prosody prosody

prosody prosody 0.9.7

prosody prosody 0.9.5

fedoraproject fedora 22

fedoraproject fedora 23

debian debian linux 8.0

debian debian linux 7.0