{"api_version":"1","generated_at":"2026-07-23T06:00:06+00:00","cve":"CVE-2017-5606","urls":{"html":"https://cve.report/CVE-2017-5606","api":"https://cve.report/api/cve/CVE-2017-5606.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-5606","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-5606"},"summary":{"title":"CVE-2017-5606","description":"An incorrect implementation of \"XEP-0280: Message Carbons\" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks. This CVE is for Xabber (only if manually enabled: 1.0.30, 1.0.30 VIP, beta 1.0.3 - 1.0.74; Android).","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2017-02-09 20:59:00","updated_at":"2020-01-22 16:01:00"},"problem_types":["CWE-20","CWE-346"],"metrics":[],"references":[{"url":"https://rt-solutions.de/en/2017/02/CVE-2017-5589_xmpp_carbons/","name":"https://rt-solutions.de/en/2017/02/CVE-2017-5589_xmpp_carbons/","refsource":"MISC","tags":["Exploit","Technical Description","Third Party Advisory"],"title":"CVE-2017-5589+ Multiple XMPP Clients User Impersonation Vulnerability – rt-solutions.de – experts you can trust","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/96186","name":"96186","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"Xabber XMPP Client CVE-2017-5606 User Impersonation Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://rt-solutions.de/wp-content/uploads/2017/02/CVE-2017-5589_xmpp_carbons.pdf","name":"https://rt-solutions.de/wp-content/uploads/2017/02/CVE-2017-5589_xmpp_carbons.pdf","refsource":"MISC","tags":["Exploit","Technical Description","Third Party Advisory"],"title":"","mime":"application/pdf","httpstatus":"200","archivestatus":"200"},{"url":"http://openwall.com/lists/oss-security/2017/02/09/29","name":"http://openwall.com/lists/oss-security/2017/02/09/29","refsource":"MISC","tags":["Exploit","Mailing List","Third Party Advisory"],"title":"oss-security - CVE-2017-5589+ Multiple XMPP Clients User Impersonation Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-5606","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-5606","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"5606","vulnerable":"1","versionEndIncluding":"1.0.30","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"xabber","cpe5":"xabber","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"-","cpe11":"android","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"5606","vulnerable":"1","versionEndIncluding":"1.0.30","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"xabber","cpe5":"xabber","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"vip","cpe11":"android","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2017-5606","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An incorrect implementation of \"XEP-0280: Message Carbons\" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks. This CVE is for Xabber (only if manually enabled: 1.0.30, 1.0.30 VIP, beta 1.0.3 - 1.0.74; Android)."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://openwall.com/lists/oss-security/2017/02/09/29","refsource":"MISC","url":"http://openwall.com/lists/oss-security/2017/02/09/29"},{"name":"96186","refsource":"BID","url":"http://www.securityfocus.com/bid/96186"},{"name":"https://rt-solutions.de/en/2017/02/CVE-2017-5589_xmpp_carbons/","refsource":"MISC","url":"https://rt-solutions.de/en/2017/02/CVE-2017-5589_xmpp_carbons/"},{"name":"https://rt-solutions.de/wp-content/uploads/2017/02/CVE-2017-5589_xmpp_carbons.pdf","refsource":"MISC","url":"https://rt-solutions.de/wp-content/uploads/2017/02/CVE-2017-5589_xmpp_carbons.pdf"}]}},"nvd":{"publishedDate":"2017-02-09 20:59:00","lastModifiedDate":"2020-01-22 16:01:00","problem_types":["CWE-20","CWE-346"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.2,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:xabber:xabber:*:*:*:*:vip:android:*:*","versionEndIncluding":"1.0.30","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:xabber:xabber:*:*:*:*:-:android:*:*","versionEndIncluding":"1.0.30","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"5606","Ordinal":"102163","Title":"CVE-2017-5606","CVE":"CVE-2017-5606","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"5606","Ordinal":"1","NoteData":"An incorrect implementation of \"XEP-0280: Message Carbons\" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks. This CVE is for Xabber (only if manually enabled: 1.0.30, 1.0.30 VIP, beta 1.0.3 - 1.0.74; Android).","Type":"Description","Title":null},{"CveYear":"2017","CveId":"5606","Ordinal":"2","NoteData":"2017-02-09","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"5606","Ordinal":"3","NoteData":"2017-02-28","Type":"Other","Title":"Modified"}]}}}