Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2016-2107

The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obtain sensitive cleartext information via a padding-oracle attack against an AES CBC session. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-0169.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.785
EPSS Ranking 99.0%
CVSS Severity
CVSS v3 Score 5.9
CVSS v2 Score 2.6
References
Products affected by CVE-2016-2107


Contact Us

Shodan ® - All rights reserved