CVE-2019-12855 describes a critical vulnerability in the XMPP support within Twisted through version 19.2.1, where TLS certificates were not properly verified, enabling Man-in-the-Middle (MITM) attacks. This vulnerability carries a high CVSS score of 7.4, indicating a high impact on confidentiality and integrity with a high attack complexity, as an unauthenticated attacker could intercept and manipulate communications. Despite its severity, there is no evidence of active exploitation, publicly available exploit code, or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 19.2.1CPE matchmatch criteria | cpe:2.3:a:twisted:twisted:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2019-12855
Jul 13, 2021Improper Certificate Validation in Twisted
Aug 16, 2019python-twisted: XMPP support in words.protocols.jabber.xmlstream in Twisted does not verify certificates allowing for a MITM connections
Jul 9, 2019In words.protocols.jabber.xmlstream in Twisted through 19.2.1 XMPP support did not verify certificates when used with TLS allowing an attacker to MITM connections.
Jun 11, 2019