CVE-2016-10593 Information

Description

ibapi is an Interactive Brokers API addon for NodeJS. ibapi downloads binary resources over HTTP which leaves it vulnerable to MITM attacks. Before 2.5.6 it may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.

CVSS Vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Reference

https://gitlord.com/commitdiff/~dchem2Fnode-ibapi-addon.git/c00dd7c98cca0423052148337e523eeb7776da68 https://gitlord.com/summary/~dchem2Fnode-ibapi-addon.git https://nodesecurity.io/advisories/182 https://www.npmjs.com/package/ibapi/v/2.5.6

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

8.1

Share on: