CVE-2016-4467 is a medium-severity vulnerability affecting the Apache Qpid Proton library (before version 0.13.1) on Windows, specifically its C client and C-based client bindings. It allows man-in-the-middle (MITM) attackers to spoof servers by presenting any valid X.509 certificate due to improper hostname verification when using the SChannel security layer. The attack requires high complexity but can lead to a complete loss of integrity (I:H). There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.8.0CPE matchmatch criteria | cpe:2.3:a:apache:qpid_proton:0.8.0:*:*:*:*:*:*:* | ||
0.9.0CPE matchmatch criteria | cpe:2.3:a:apache:qpid_proton:0.9.0:*:*:*:*:*:*:* | ||
0.9.1CPE matchmatch criteria | cpe:2.3:a:apache:qpid_proton:0.9.1:*:*:*:*:*:*:* | ||
0.10.0CPE matchmatch criteria | cpe:2.3:a:apache:qpid_proton:0.10.0:*:*:*:*:*:*:* | ||
0.11.0CPE matchmatch criteria | cpe:2.3:a:apache:qpid_proton:0.11.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.