{"api_version":"1","generated_at":"2026-07-23T08:08:31+00:00","cve":"CVE-2017-5591","urls":{"html":"https://cve.report/CVE-2017-5591","api":"https://cve.report/api/cve/CVE-2017-5591.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-5591","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-5591"},"summary":{"title":"CVE-2017-5591","description":"An incorrect implementation of \"XEP-0280: Message Carbons\" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks. This CVE is for SleekXMPP up to 1.3.1 and Slixmpp all versions up to 1.2.3, as bundled in poezio (0.8 - 0.10) and other products.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2017-02-09 20:59:00","updated_at":"2020-01-22 14:13:00"},"problem_types":["CWE-20","CWE-346"],"metrics":[],"references":[{"url":"https://rt-solutions.de/en/2017/02/CVE-2017-5589_xmpp_carbons/","name":"https://rt-solutions.de/en/2017/02/CVE-2017-5589_xmpp_carbons/","refsource":"MISC","tags":["Exploit","Technical Description","Third Party Advisory"],"title":"CVE-2017-5589+ Multiple XMPP Clients User Impersonation Vulnerability – rt-solutions.de – experts you can trust","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/96166","name":"96166","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"Poezio/SleekXMPP/Slixmpp CVE-2017-5591 User Impersonation Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://rt-solutions.de/wp-content/uploads/2017/02/CVE-2017-5589_xmpp_carbons.pdf","name":"https://rt-solutions.de/wp-content/uploads/2017/02/CVE-2017-5589_xmpp_carbons.pdf","refsource":"MISC","tags":["Exploit","Technical Description","Third Party Advisory"],"title":"","mime":"application/pdf","httpstatus":"200","archivestatus":"200"},{"url":"http://openwall.com/lists/oss-security/2017/02/09/29","name":"http://openwall.com/lists/oss-security/2017/02/09/29","refsource":"MISC","tags":["Exploit","Mailing List","Third Party Advisory"],"title":"oss-security - CVE-2017-5589+ Multiple XMPP Clients User Impersonation Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/poezio/slixmpp/commit/22664ee7b86c8e010f312b66d12590fb47160ad8","name":"https://github.com/poezio/slixmpp/commit/22664ee7b86c8e010f312b66d12590fb47160ad8","refsource":"MISC","tags":["Patch"],"title":"Fix carbons · poezio/slixmpp@22664ee · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-5591","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-5591","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"5591","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"poezio","cpe5":"poezio","cpe6":"0.10","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"5591","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"poezio","cpe5":"poezio","cpe6":"0.8","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"5591","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"poezio","cpe5":"poezio","cpe6":"0.8.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"5591","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"poezio","cpe5":"poezio","cpe6":"0.9","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"5591","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"poezio","cpe5":"poezio","cpe6":"0.10","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"5591","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"poezio","cpe5":"poezio","cpe6":"0.8","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"5591","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"poezio","cpe5":"poezio","cpe6":"0.8.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"5591","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"poezio","cpe5":"poezio","cpe6":"0.9","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"5591","vulnerable":"1","versionEndIncluding":"1.3.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sleekxmpp_project","cpe5":"sleekxmpp","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"5591","vulnerable":"1","versionEndIncluding":"1.2.3","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"slixmpp_project","cpe5":"slixmpp","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2017-5591","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An incorrect implementation of \"XEP-0280: Message Carbons\" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks. This CVE is for SleekXMPP up to 1.3.1 and Slixmpp all versions up to 1.2.3, as bundled in poezio (0.8 - 0.10) and other products."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"96166","refsource":"BID","url":"http://www.securityfocus.com/bid/96166"},{"name":"http://openwall.com/lists/oss-security/2017/02/09/29","refsource":"MISC","url":"http://openwall.com/lists/oss-security/2017/02/09/29"},{"name":"https://rt-solutions.de/en/2017/02/CVE-2017-5589_xmpp_carbons/","refsource":"MISC","url":"https://rt-solutions.de/en/2017/02/CVE-2017-5589_xmpp_carbons/"},{"name":"https://rt-solutions.de/wp-content/uploads/2017/02/CVE-2017-5589_xmpp_carbons.pdf","refsource":"MISC","url":"https://rt-solutions.de/wp-content/uploads/2017/02/CVE-2017-5589_xmpp_carbons.pdf"},{"name":"https://github.com/poezio/slixmpp/commit/22664ee7b86c8e010f312b66d12590fb47160ad8","refsource":"MISC","url":"https://github.com/poezio/slixmpp/commit/22664ee7b86c8e010f312b66d12590fb47160ad8"}]}},"nvd":{"publishedDate":"2017-02-09 20:59:00","lastModifiedDate":"2020-01-22 14:13:00","problem_types":["CWE-20","CWE-346"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.2,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:sleekxmpp_project:sleekxmpp:*:*:*:*:*:*:*:*","versionEndIncluding":"1.3.1","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:slixmpp_project:slixmpp:*:*:*:*:*:*:*:*","versionEndIncluding":"1.2.3","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:poezio:poezio:0.8.1:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:poezio:poezio:0.8:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:poezio:poezio:0.9:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:poezio:poezio:0.10:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"5591","Ordinal":"102148","Title":"CVE-2017-5591","CVE":"CVE-2017-5591","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"5591","Ordinal":"1","NoteData":"An incorrect implementation of \"XEP-0280: Message Carbons\" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks. This CVE is for SleekXMPP up to 1.3.1 and Slixmpp all versions up to 1.2.3, as bundled in poezio (0.8 - 0.10) and other products.","Type":"Description","Title":null},{"CveYear":"2017","CveId":"5591","Ordinal":"2","NoteData":"2017-02-09","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"5591","Ordinal":"3","NoteData":"2017-02-28","Type":"Other","Title":"Modified"}]}}}