Authentication Bypass Vulnerability in nefarious2 IRC Server

Authentication Bypass Vulnerability in nefarious2 IRC Server

CVE-2016-7145 · HIGH Severity

AV:N/AC:L/AU:N/C:P/I:P/A:P

The m_authenticate function in ircd/m_authenticate.c in nefarious2 allows remote attackers to spoof certificate fingerprints and consequently log in as another user via a crafted AUTHENTICATE parameter.

Learn more about our User Device Pen Test.