CVE-2016-10690 affects the openframe-ascii-image module, an openframe plugin designed to display ASCII images. This vulnerability stems from the module's insecure practice of downloading resources over unencrypted HTTP, making it susceptible to Man-in-the-Middle (MITM) attacks. A successful MITM attack could allow an adversary to substitute legitimate resources with malicious ones, potentially leading to remote code execution (RCE) with high impact on confidentiality, integrity, and availability. While rated with a CVSS score of 8.1 (HIGH), there is no evidence of active exploitation, nor are there known public exploits or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.1.0CPE matchmatch criteria | cpe:2.3:a:openframe-ascii-image_project:openframe-ascii-image:0.1.0:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.