V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2016-10588
CVE
High

nw is an installer for nw.js. nw downloads zipped resources over HTTP, It may be possible to cause remote code execution (RCE) by swapping …

CVSS
8.1
High
EPSS
0.01
p75
Published
2016-01-01
Updated
2016-01-01
Description

nw is an installer for nw.js. nw downloads zipped resources over HTTP, It may be possible to cause remote code execution (RCE) by swapping out the requested zip file with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.

Tags · CWE
Pre-auth
CWE-311
CAPEC-31
CAPEC-37
CAPEC-65
CAPEC-157
CAPEC-158
CAPEC-204
CAPEC-383
CAPEC-384
CAPEC-385
CAPEC-386
CAPEC-387
CAPEC-388
CAPEC-477
CAPEC-609
Affected products
Nw > 0.23.6-1
CVSS vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2016-01-01
Published
2016-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: H
High (H)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.009 · p75
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-37 · CWE-311
└ via CAPEC-65 · CWE-311
└ via CAPEC-383 · CWE-311
└ via CAPEC-31 · CWE-311
└ via CAPEC-37 · CWE-311
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected software
ProductVendorStatus
nw*Tracked
Source databases
CVE