{"api_version":"1","generated_at":"2026-04-23T02:35:40+00:00","cve":"CVE-2016-6650","urls":{"html":"https://cve.report/CVE-2016-6650","api":"https://cve.report/api/cve/CVE-2016-6650.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2016-6650","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2016-6650"},"summary":{"title":"CVE-2016-6650","description":"EMC RecoverPoint versions prior to 5.0 and EMC RecoverPoint for Virtual Machines versions prior to 5.0 have an SSL Stripping Vulnerability that may potentially be exploited by malicious users to compromise the affected system.","state":"PUBLIC","assigner":"security_alert@emc.com","published_at":"2017-03-21 16:59:00","updated_at":"2017-07-12 01:29:00"},"problem_types":["CWE-200"],"metrics":[],"references":[{"url":"http://www.securitytracker.com/id/1038066","name":"1038066","refsource":"SECTRACK","tags":[],"title":"EMC RecoverPoint Flaw Lets Remote Users Conduct SSL Stripping Attacks to Access and Modify Data - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/96156","name":"96156","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"EMC RecoverPoint SSL Stripping CVE-2016-6650 Security Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.securityfocus.com/archive/1/540303/30/0/threaded","name":"http://www.securityfocus.com/archive/1/540303/30/0/threaded","refsource":"CONFIRM","tags":["Mitigation","Third Party Advisory","VDB Entry"],"title":"SecurityFocus","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2016-6650","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2016-6650","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2016","cve_id":"6650","vulnerable":"1","versionEndIncluding":"4.4.1.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"emc","cpe5":"recoverpoint","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"6650","vulnerable":"1","versionEndIncluding":"4.4.1.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"emc","cpe5":"recoverpoint_for_virtual_machines","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"security_alert@emc.com","ID":"CVE-2016-6650","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"EMC RecoverPoint versions prior to 5.0 and EMC RecoverPoint for Virtual Machines versions prior to 5.0","version":{"version_data":[{"version_value":"EMC RecoverPoint versions prior to 5.0 and EMC RecoverPoint for Virtual Machines versions prior to 5.0"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"EMC RecoverPoint versions prior to 5.0 and EMC RecoverPoint for Virtual Machines versions prior to 5.0 have an SSL Stripping Vulnerability that may potentially be exploited by malicious users to compromise the affected system."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"SSL Stripping Vulnerability"}]}]},"references":{"reference_data":[{"name":"1038066","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1038066"},{"name":"http://www.securityfocus.com/archive/1/540303/30/0/threaded","refsource":"CONFIRM","url":"http://www.securityfocus.com/archive/1/540303/30/0/threaded"},{"name":"96156","refsource":"BID","url":"http://www.securityfocus.com/bid/96156"}]}},"nvd":{"publishedDate":"2017-03-21 16:59:00","lastModifiedDate":"2017-07-12 01:29:00","problem_types":["CWE-200"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":1.6,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:H/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":2.6},"severity":"LOW","exploitabilityScore":4.9,"impactScore":2.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:emc:recoverpoint_for_virtual_machines:*:*:*:*:*:*:*:*","versionEndIncluding":"4.4.1.1","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:emc:recoverpoint:*:*:*:*:*:*:*:*","versionEndIncluding":"4.4.1.1","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2016","CveId":"6650","Ordinal":"92955","Title":"CVE-2016-6650","CVE":"CVE-2016-6650","Year":"2016"},"notes":[{"CveYear":"2016","CveId":"6650","Ordinal":"1","NoteData":"EMC RecoverPoint versions prior to 5.0 and EMC RecoverPoint for Virtual Machines versions prior to 5.0 have an SSL Stripping Vulnerability that may potentially be exploited by malicious users to compromise the affected system.","Type":"Description","Title":null},{"CveYear":"2016","CveId":"6650","Ordinal":"2","NoteData":"2017-03-21","Type":"Other","Title":"Published"},{"CveYear":"2016","CveId":"6650","Ordinal":"3","NoteData":"2017-07-11","Type":"Other","Title":"Modified"}]}}}