CVE-2016-6271 describes a critical vulnerability in the Bzrtp library (libbzrtp) versions prior to 1.0.4, allowing man-in-the-middle (MitM) attackers to perform spoofing attacks. This flaw stems from a missing HVI check during DHPart2 packet reception, enabling attackers to impersonate legitimate communication endpoints. With a CVSS score of 7.5 (High), the vulnerability is easily exploitable over the network with low attack complexity, potentially leading to high integrity impacts without requiring user interaction. While no public exploits are currently available in Metasploit or ExploitDB, and it is not listed in CISA's KEV catalog, there is some community discussion indicating awareness of the issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.0CPE matchmatch criteria | cpe:2.3:a:bzrtp_project:bzrtp:1.0.0:*:*:*:*:*:*:* | ||
1.0.2CPE matchmatch criteria | cpe:2.3:a:bzrtp_project:bzrtp:1.0.2:*:*:*:*:*:*:* | ||
1.0.3CPE matchmatch criteria | cpe:2.3:a:bzrtp_project:bzrtp:1.0.3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.