CVE-2016-10593 affects the ibapi NodeJS addon for Interactive Brokers, stemming from its insecure practice of downloading binary resources over HTTP. This vulnerability allows for potential remote code execution (RCE) through Man-in-the-Middle (MITM) attacks, where an attacker can replace legitimate binaries with malicious ones. Rated with a CVSS score of 8.1 (High), exploitation requires an attacker to be positioned on the network, but does not require user interaction. While the vulnerability is severe, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding it.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.4.2CPE matchmatch criteria | cpe:2.3:a:interactivebrokers:ibapi:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.