CVE-2016-5672 describes a critical vulnerability in Intel Crosswalk versions before 19.49.514.5, 20.x before 20.50.533.11, 21.x before 21.51.546.0, and 22.x before 22.51.549.0. This flaw allows a user's acceptance of a single invalid X.509 certificate to implicitly approve all subsequent invalid certificates, making it significantly easier for man-in-the-middle (MitM) attackers to spoof SSL servers. With a CVSS v3.0 score of 8.1 (HIGH), the vulnerability has a network attack vector, low attack complexity, and requires user interaction, potentially leading to high confidentiality and integrity impacts. While there is no evidence of active exploitation, public exploit code, or Metasploit modules, the vulnerability has garnered some community discussion and media coverage, indicating awareness of its potential.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 19.49.514.4CPE matchmatch criteria | cpe:2.3:a:intel:crosswalk:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.