4.3
CVSSv2

CVE-2016-4467

Published: 02/05/2017 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The C client and C-based client bindings in the Apache Qpid Proton library prior to 0.13.1 on Windows do not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate when using the SChannel-based security layer, which allows man-in-the-middle malicious users to spoof servers via an arbitrary valid certificate.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache qpid proton 0.12.0

apache qpid proton 0.12.1

apache qpid proton 0.13.0

apache qpid proton 0.11.1

apache qpid proton 0.11.0

apache qpid proton 0.10.0

apache qpid proton 0.9.1

apache qpid proton 0.12.2

apache qpid proton 0.9.0

apache qpid proton 0.8.0