Vulnerability Details CVE-2017-5590
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks. This CVE is for ChatSecure (3.2.0 - 4.0.0; only iOS) and Zom (all versions up to 1.0.11; only iOS).
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 58.9%
CVSS Severity
CVSS v3 Score 5.9
CVSS v2 Score 4.3
Products affected by CVE-2017-5590
-
cpe:2.3:a:chatsecure:chatsecure:3.2.0
-
cpe:2.3:a:chatsecure:chatsecure:3.2.1
-
cpe:2.3:a:chatsecure:chatsecure:3.2.2
-
cpe:2.3:a:chatsecure:chatsecure:3.2.3
-
cpe:2.3:a:chatsecure:chatsecure:4.0.0
-
-
-
-
-
-
-
-
-