Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2017-5590

An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks. This CVE is for ChatSecure (3.2.0 - 4.0.0; only iOS) and Zom (all versions up to 1.0.11; only iOS).
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 58.9%
CVSS Severity
CVSS v3 Score 5.9
CVSS v2 Score 4.3
References
Products affected by CVE-2017-5590
  • Chatsecure » Chatsecure » Version: 3.2.0
    cpe:2.3:a:chatsecure:chatsecure:3.2.0
  • Chatsecure » Chatsecure » Version: 3.2.1
    cpe:2.3:a:chatsecure:chatsecure:3.2.1
  • Chatsecure » Chatsecure » Version: 3.2.2
    cpe:2.3:a:chatsecure:chatsecure:3.2.2
  • Chatsecure » Chatsecure » Version: 3.2.3
    cpe:2.3:a:chatsecure:chatsecure:3.2.3
  • Chatsecure » Chatsecure » Version: 4.0.0
    cpe:2.3:a:chatsecure:chatsecure:4.0.0
  • Zom » Zom » Version: 1.0.10
    cpe:2.3:a:zom:zom:1.0.10
  • Zom » Zom » Version: 1.0.11
    cpe:2.3:a:zom:zom:1.0.11
  • Zom » Zom » Version: 1.0.3
    cpe:2.3:a:zom:zom:1.0.3
  • Zom » Zom » Version: 1.0.4
    cpe:2.3:a:zom:zom:1.0.4
  • Zom » Zom » Version: 1.0.5
    cpe:2.3:a:zom:zom:1.0.5
  • Zom » Zom » Version: 1.0.6
    cpe:2.3:a:zom:zom:1.0.6
  • Zom » Zom » Version: 1.0.7
    cpe:2.3:a:zom:zom:1.0.7
  • Zom » Zom » Version: 1.0.8
    cpe:2.3:a:zom:zom:1.0.8
  • Zom » Zom » Version: 1.0.9
    cpe:2.3:a:zom:zom:1.0.9


Contact Us

Shodan ® - All rights reserved