CVE-2016-3698
—CVSS 3.0
8.1 high
EPSS
4%p89
Published
()
Modified
Description
libndp before 1.6, as used in NetworkManager, does not properly validate the origin of Neighbor Discovery Protocol (NDP) messages, which allows remote attackers to conduct man-in-the-middle attacks or cause a denial of service (network connectivity disruption) by advertising a node as a router from a non-local network.
- Vendors
- redhatlibndpdebiancanonical
- Products
- enterprise linux desktop, enterprise linux hpc node, enterprise linux hpc node eus, enterprise linux server, enterprise linux server aus, enterprise linux server eus, enterprise linux workstation, libndp, debian linux, ubuntu linux
- Weakness
- CWE-284
- Vector
- CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.