CVE-2016-10600: Critical severity webrtc vulnerability
webrtc-native uses WebRTC from chromium project. webrtc-native downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2016-10600.
What is the severity of CVE-2016-10600?
The severity of CVE-2016-10600 is critical with a score of 8.1.
What software is affected by CVE-2016-10600?
Webrtc Webrtc-native version up to 1.4.0 on Node.js is affected by CVE-2016-10600.
How does CVE-2016-10600 leave the system vulnerable?
CVE-2016-10600 leaves the system vulnerable to MITM attacks by downloading binary resources over HTTP.
What is the potential impact of CVE-2016-10600?
CVE-2016-10600 may allow remote code execution (RCE) if an attacker swaps out the requested binary with a malicious one.