V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2016-10624
CVE
High

selenium-chromedriver is a simple utility for downloading the Selenium Webdriver for Google Chrome selenium-chromedriver downloads binary r…

CVSS
7.4
High
EPSS
0.02
p79
Published
2016-01-01
Updated
2016-01-01
Description

selenium-chromedriver is a simple utility for downloading the Selenium Webdriver for Google Chrome selenium-chromedriver downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.

Tags · CWE
Pre-auth
CWE-300
CWE-311
CAPEC-31
CAPEC-37
CAPEC-57
CAPEC-65
CAPEC-94
CAPEC-157
CAPEC-158
CAPEC-204
CAPEC-383
CAPEC-384
CAPEC-385
CAPEC-386
CAPEC-387
CAPEC-388
CAPEC-466
CAPEC-477
CAPEC-589
CAPEC-590
CAPEC-609
CAPEC-612
CAPEC-613
CAPEC-615
CAPEC-662
Affected products
Selenium-chromedriver
CVSS vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Timeline
2016-01-01
Published
2016-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: H
High (H)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.021 · p79
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-37 · CWE-311
└ via CAPEC-57 · CWE-300
└ via CAPEC-383 · CWE-311
└ via CAPEC-662 · CWE-300
└ via CAPEC-31 · CWE-311
└ via CAPEC-37 · CWE-311
└ via CAPEC-94 · CWE-300
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
selenium-chromedriver*Tracked
Source databases
CVE