CVE-2016-7142
MEDIUMInspircd < 2.0.22 - Access Control
Title source: ruleDescription
The m_sasl module in InspIRCd before 2.0.23, when used with a service that supports SASL_EXTERNAL authentication, allows remote attackers to spoof certificate fingerprints and consequently log in as another user via a crafted SASL message.
References (5)
Scores
CVSS v3
5.9
EPSS
0.0014
EPSS Percentile
33.4%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Classification
CWE
CWE-264
Status
published
Affected Products (3)
inspircd/inspircd
< 2.0.22
debian/debian_linux
n/a/n/a
Timeline
Published
Sep 26, 2016
Tracked Since
Feb 18, 2026