CVE-2017-15397

7.4HIGH

Key Information:

Vendor
Google
Vendor
CVE Published:
7 February 2018

Summary

Inappropriate implementation in ChromeVox in Google Chrome OS prior to 62.0.3202.74 allowed a remote attacker in a privileged network position to observe or tamper with certain cleartext HTTP requests by leveraging that position.

Affected Version(s)

Google Chrome OS prior to 62.0.3202.74 Google Chrome OS prior to 62.0.3202.74

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.