CyberRota
Live Feed
Return to register
Case File

CVE-2016-0772

MEDIUM · CVSS 6.5 EPSS 15.03%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2016-09-02 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2016-0772
Severity
MEDIUM
CVSS
6.5
EPSS
15.03%

Original Filing — NVD Description

The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an error when StartTLS fails, which might allow man-in-the-middle attackers to bypass the TLS protections by leveraging a network position between the client and the registry to block the StartTLS command, aka a "StartTLS stripping attack."