peter bassill · operator
$ cve CVE-2016-2107 JSON

CVE-2016-2107 EXPLOIT

5.9
MEDIUM · CVSS 3.1 · EPSS 89.1% (pctl 100)

Patch early

A public exploit exists.

Description

The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obtain sensitive cleartext information via a padding-oracle attack against an AES CBC session. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-0169.

Scoring

CVSS5.9 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS89.06% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-200
On CISA KEVno
Public exploityes
Published2016-05-05
Last modified2026-06-17

Affected (15)

VendorProduct
canonicalubuntu linux
debiandebian linux
googleandroid
hphelion openstack
nodejsnode.js
opensslopenssl
opensuseleap
opensuseopensuse
redhatenterprise linux desktop
redhatenterprise linux hpc node
redhatenterprise linux hpc node eus
redhatenterprise linux server
redhatenterprise linux server aus
redhatenterprise linux server eus
redhatenterprise linux workstation

Public exploits

SourceTitleDate
exploit-dbOpenSSL - Padding Oracle in AES-NI CBC MAC Check2016-05-04

References

→ the Explorer  ·  watch your stack  ·  NVD