CVE-2017-16031
CVE-2017-16031
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 2.0%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
04 Jun 2018Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Socket.io is a realtime application framework that provides communication via websockets. Because socket.io 0.9.6 and earlier depends on `Math.random()` to create socket IDs, the IDs are predictable. An attacker is able to guess the socket ID and gain access to socket.io servers, potentially obtaining sensitive information.
Affected products
HackerOne · socket.io node moduleWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →