CVE-2016-2107
published 2016-05-05CVE-2016-2107: The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows…
PriorityP262medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EXPLOIT
EPSS
89.06%
99.8th percentile
The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obtain sensitive cleartext information via a padding-oracle attack against an AES CBC session. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-0169.
Affected
68 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | os_x_el_capitan_v10.11.6_and_security_update_2016-004 | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | openssl | < openssl 1.0.2h-1 (bookworm) | openssl 1.0.2h-1 (bookworm) |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The attack targets TLS/SSL and DTLS sessions using AES CBC cipher suites (e.g., TLS_RSA_WITH_AES_128_CBC_SHA, TLS_RSA_WITH_AES_256_CBC_SHA, TLS_RSA_WITH_AES_128_CBC_SHA256, TLS_RSA_WITH_AES_256_CBC_SHA256). Monitor for anomalous patterns of repeated TLS handshakes or alert messages from a single client against an AES-NI-capable server, which may indicate a padding oracle probing attack. ↗
- →The PoC exploit sends a malformed Finished message containing 32 bytes of 0x3F as the explicit plaintext value. Detection of a TLS Finished message payload consisting entirely of 0x3F bytes is a strong indicator of CVE-2016-2107 exploitation attempts. ↗
- →A MITM attacker exploiting this vulnerability will generate a high volume of TLS connections to the target server, observing differing alert responses to distinguish valid from invalid padding. Detect by monitoring for large numbers of TLS alert messages (especially bad_record_mac) from a single source IP in a short time window against an AES CBC session. ↗
- →The vulnerability is only exploitable when the server supports AES-NI hardware acceleration and uses AES CBC cipher suites. Audit server TLS configurations to identify exposure; servers lacking AES-NI are not vulnerable to this specific attack path. ↗
- ·Only OpenSSL versions before 1.0.1t and 1.0.2 before 1.0.2h are vulnerable. The flaw is specifically in the AES-NI CBC MAC padding check code path; servers without AES-NI hardware support are not affected by this particular vulnerability. ↗
- ·The vulnerability exists because of an incorrect fix for CVE-2013-0169 (Lucky Thirteen). The padding check was rewritten to be constant-time but no longer verified that sufficient data existed for both MAC and padding bytes. ↗
- ·The attack requires a MITM position; a remote attacker cannot exploit this vulnerability without being able to intercept and modify traffic between the client and the vulnerable server. ↗
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian2.6LOW
vendor_redhat2.6LOW
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SCALANCE X-200RNA Switch Devices
cisa_ics·2022-12-19
Siemens SCALANCE X-200RNA Switch Devices
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SCALANCE X-200RNA Switch Devices
Last RevisedDecember 19, 2022
Alert CodeICSA-22-349-21
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity/public exploits are available
- Vendor: Siemens
- Equipment: SCALANCE X-200RNA switch devices before V3.2.7
- Vulnerabilities: Observable Timing Discrepancy; Race Condition; Improper Restriction of Operations within the Bounds of a Memory Buffer; Improper Input Validation; NULL Pointer Dereference; Use After Free; Cryptographic Issues; Comparison of Incompatible Types; Resource Management
Palo Alto
PAN-SA-2016-0023 OpenSSL Vulnerabilities
vendor_paloalto·2016-09-02·CVSS 2.6
CVE-2013-0169 [LOW] CWE-119 PAN-SA-2016-0023 OpenSSL Vulnerabilities
PAN-SA-2016-0023 OpenSSL Vulnerabilities
The OpenSSL library embedded in the GlobalProtect™ agent, TerminalServer™ agent and UserID™ agent is
CVEs: CVE-2013-0169, CVE-2016-2105, CVE-2016-2106, CVE-2016-2107, CVE-2016-2109, CVE-2016-2176
Affected products: GlobalProtect
Palo Alto
PAN-SA-2016-0020 OpenSSL Vulnerabilities
vendor_paloalto·2016-08-15·CVSS 7.5
CVE-2014-8176 [HIGH] CWE-119 PAN-SA-2016-0020 OpenSSL Vulnerabilities
PAN-SA-2016-0020 OpenSSL Vulnerabilities
The OpenSSL library has been found to contain several vulnerabilities CVE-2014-8176, CVE-2015-1788, CVE-2015-1789, CVE-2015-1790, CVE-2015-1791, CVE-2015-1792, CVE-2015-1794, CVE-2015-3195, CVE-2015-4000, CVE-2016-2105, CVE-2016-2106, CVE-2016-2107, CVE-2016-2108, CVE-2016-2109, CVE-2016-2176, CVE-2016-2842. Palo Alto Networks software makes use of the vulnerable library. (Ref # 95622). The OpenSSL library in use by PAN-OS is patched on a regular basis. Severities of the CVEs listed under the summary section range from low to high but, have not been shown to be exploitable at the time of this advisory. This issue affects PAN-OS 5.0.X; PAN-OS-5.1.X; PAN-OS 6.0.13 and earlier; PAN-OS 6.1.12 and earlier; PAN-OS 7.0.8 and earlier; PAN-OS 7.1.3 and earl
Apple
CVE-2016-2107: OS X El Capitan v10.11.6 and Security Update 2016-004
vendor_apple·2016-07-18·CVSS 5.9
CVE-2016-2107 [MEDIUM] CVE-2016-2107: OS X El Capitan v10.11.6 and Security Update 2016-004
Apple Security Update: About the security content of OS X El Capitan v10.11.6 and Security Update 2016-004
Product: OS X El Capitan v10.11.6 and Security Update 2016-004
CVE: CVE-2016-2107
Component: OpenSSL
Impact: A remote attacker may be able to execute arbitrary code
Description: Multiple issues existed in OpenSSL. These issues were resolved by backporting the fixes from OpenSSL 1.0.2h/1.0.1 to OpenSSL 0.9.8.
Android
CVE-2016-2107: Android Security Bulletin 2016-07-01
CVE: CVE-2016-2107
Severity: HIGH
Affected AOSP versions: 4
vendor_android·2016-07-01·CVSS 5.9
CVE-2016-2107 [MEDIUM] CVE-2016-2107: Android Security Bulletin 2016-07-01
CVE: CVE-2016-2107
Severity: HIGH
Affected AOSP versions: 4
Android Security Bulletin 2016-07-01
CVE: CVE-2016-2107
Severity: HIGH
Affected AOSP versions: 4.4.4, 5.0.2, 5.1.1
References: A-28550804
BSD
FreeBSD-SA-16:17.openssl: Multiple OpenSSL vulnerabilities
bsd_advisories·2016-05-04·CVSS 7.5
CVE-2016-2105 [HIGH] FreeBSD-SA-16:17.openssl: Multiple OpenSSL vulnerabilities
FreeBSD-SA-16:17.openssl Security Advisory
The FreeBSD Project
Topic: Multiple OpenSSL vulnerabilities
Category: contrib
Module: openssl
Announced: 2016-05-04
Credits: OpenSSL Project
Affects: All supported versions of FreeBSD.
Corrected: 2016-05-03 18:54:20 UTC (stable/10, 10.3-STABLE)
2016-05-04 15:25:47 UTC (releng/10.3, 10.3-RELEASE-p2)
2016-05-04 15:26:23 UTC (releng/10.2, 10.2-RELEASE-p16)
2016-05-04 15:27:09 UTC (releng/10.1, 10.1-RELEASE-p33)
2016-05-04 06:53:02 UTC (stable/9, 9.3-STABLE)
2016-05-04 15:27:09 UTC (releng/9.3, 9.3-RELEASE-p41)
CVE Name: CVE-2016-2105, CVE-2016-2106, CVE-2016-2107, CVE-2016-2109,
CVE-2016-2176
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, ple
Cisco
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: May 2016
vendor_cisco·2016-05-04
CVE-2016-2105 [MEDIUM] CWE-119 Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: May 2016
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: May 2016
On May 3, 2016, the OpenSSL Software Foundation released a security advisory that included six vulnerabilities. Of the six vulnerabilities disclosed, four of them may cause memory corruption or excessive memory usage, one could allow a padding oracle attack to decrypt traffic when the connection uses an AES CBC cipher and the server supports AES-NI, and, lastly, one is specific to a product performing an operation with Extended Binary Coded Decimal Interchange Code (EBCDIC) encoding.
Multiple Cisco products incorporate a version of the OpenSSL package affected by one or more vulnerabilities.
This advisory will be updated as additional information becomes available.
This advisory is available at the following link:
Red Hat
openssl: Padding oracle in AES-NI CBC MAC check
vendor_redhat·2016-05-03·CVSS 2.6
CVE-2016-2107 [LOW] openssl: Padding oracle in AES-NI CBC MAC check
openssl: Padding oracle in AES-NI CBC MAC check
The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obtain sensitive cleartext information via a padding-oracle attack against an AES CBC session. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-0169.
It was discovered that OpenSSL leaked timing information when decrypting TLS/SSL and DTLS protocol encrypted records when the connection used the AES CBC cipher suite and the server supported AES-NI. A remote attacker could possibly use this flaw to retrieve plain text from encrypted packets by using a TLS/SSL or DTLS server as a padding oracle.
Package: openssl (Red Hat Enterprise Linux 4) - Not
Ubuntu
OpenSSL vulnerabilities
vendor_ubuntu·2016-05-03·CVSS 7.5
CVE-2016-2105 [HIGH] OpenSSL vulnerabilities
Title: OpenSSL vulnerabilities
Summary: Several security issues were fixed in OpenSSL.
Huzaifa Sidhpurwala, Hanno Böck, and David Benjamin discovered that OpenSSL
incorrectly handled memory when decoding ASN.1 structures. A remote
attacker could use this issue to cause OpenSSL to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2016-2108)
Juraj Somorovsky discovered that OpenSSL incorrectly performed padding when
the connection uses the AES CBC cipher and the server supports AES-NI. A
remote attacker could possibly use this issue to perform a padding oracle
attack and decrypt traffic. (CVE-2016-2107)
Guido Vranken discovered that OpenSSL incorrectly handled large amounts of
input data to the EVP_EncodeUpdate() function. A remote attacker could use
this
Debian
CVE-2016-2107: openssl - The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does ...
vendor_debian·2016·CVSS 2.6
CVE-2016-2107 [LOW] CVE-2016-2107: openssl - The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does ...
The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obtain sensitive cleartext information via a padding-oracle attack against an AES CBC session. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-0169.
Scope: local
bookworm: resolved (fixed in 1.0.2h-1)
bullseye: resolved (fixed in 1.0.2h-1)
forky: resolved (fixed in 1.0.2h-1)
sid: resolved (fixed in 1.0.2h-1)
trixie: resolved (fixed in 1.0.2h-1)
Cisco
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: May 2016
vendor_cisco
CVE-2016-2107 Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: May 2016
CVE-2016-2107: Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: May 2016
On May 3, 2016, the OpenSSL Software Foundation released a security advisory that included six vulnerabilities. Of the six vulnerabilities disclosed, four of them may cause memory corruption or excessive memory usage, one could allow a padding oracle attack to decrypt traffic when the connection uses an AES CBC cipher and the server supports AES-NI, and, lastly, one is specific to a product performing an operation with Extended Binary Coded Decimal Interchange Code (EBCDIC) encoding. Multiple Cisco products incorporate a version of the OpenSSL package affected by one or more vulnerabilities. This advisory will be updated as additional information becomes available. This advisory is available at the follow
GHSA
GHSA-3gm7-8cfv-p8h9: The AES-NI implementation in OpenSSL before 1
ghsa_unreviewed·2022-05-14·CVSS 2.6
CVE-2016-2107 [LOW] CWE-200 GHSA-3gm7-8cfv-p8h9: The AES-NI implementation in OpenSSL before 1
The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obtain sensitive cleartext information via a padding-oracle attack against an AES CBC session. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-0169.
OSV
CVE-2016-2107: The AES-NI implementation in OpenSSL before 1
osv·2016-05-05·CVSS 2.6
CVE-2016-2107 [LOW] CVE-2016-2107: The AES-NI implementation in OpenSSL before 1
The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obtain sensitive cleartext information via a padding-oracle attack against an AES CBC session. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-0169.
OSV
openssl vulnerabilities
osv·2016-05-03·CVSS 7.5
CVE-2016-2108 [HIGH] openssl vulnerabilities
openssl vulnerabilities
Huzaifa Sidhpurwala, Hanno Böck, and David Benjamin discovered that OpenSSL
incorrectly handled memory when decoding ASN.1 structures. A remote
attacker could use this issue to cause OpenSSL to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2016-2108)
Juraj Somorovsky discovered that OpenSSL incorrectly performed padding when
the connection uses the AES CBC cipher and the server supports AES-NI. A
remote attacker could possibly use this issue to perform a padding oracle
attack and decrypt traffic. (CVE-2016-2107)
Guido Vranken discovered that OpenSSL incorrectly handled large amounts of
input data to the EVP_EncodeUpdate() function. A remote attacker could use
this issue to cause OpenSSL to crash, resulting in a denial of servic
No detection rules found.
HackerOne
formassembly.com is vulnerable to padding-oracle attacks.
hackerone·2017-03-17·CVSS 5.9
CVE-2016-2107 [MEDIUM] formassembly.com is vulnerable to padding-oracle attacks.
formassembly.com is vulnerable to padding-oracle attacks.
Dear Formassembly bug bounty team,
# Summary
---
formassembly.com is vulnerable to CVE-2016-2107, allowing remote attackers to obtain sensitive information via padding-oracle attacks.
~~~
$ git clone https://github.com/FiloSottile/CVE-2016-2107.git
$ go run main.go www.formassembly.com
... Vulnerable: true
~~~
The code above checks whether the TLS alert is `DATA_LENGTH_TOO_LONG` (vulnerable) or `BAD_RECORD_MAC` (not vulnerable).
# What is CVE-2016-2107?
---
Filippo Valsorda, the author of the tool I used to discover this issue, wrote a fantastic article on CVE-2016-2107 here: https://blog.cloudflare.com/yet-another-padding-oracle-in-openssl-cbc-ciphersuites/
# What are padding-oracle attacks?
---
During the decryption and t
HackerOne
Padding oracle in AES-NI CBC MAC check (CVE-2016-2107)
hackerone·2016-05-19·CVSS 2.6
CVE-2016-2107 [LOW] Padding oracle in AES-NI CBC MAC check (CVE-2016-2107)
Padding oracle in AES-NI CBC MAC check (CVE-2016-2107)
Advisory: https://www.openssl.org/news/secadv/20160503.txt
Writeup (Referencing a proof of concept): http://web-in-security.blogspot.de/2016/05/curious-padding-oracle-in-openssl-cve.html
A MITM attacker can use a padding oracle attack to decrypt traffic when the connection uses an AES CBC cipher and the server support AES-NI.
This issue was introduced as part of the fix for Lucky 13 padding attack (CVE-2013-0169). The padding check was rewritten to be in constant time by making sure that always the same bytes are read and compared against either the MAC or padding bytes. But it no longer checked that there was enough data to have both the MAC and padding bytes.
OpenSSL 1.0.2 users should upgrade to 1.0.2h
OpenSSL 1.0.1 users should
Bugzilla
CVE-2016-2105 CVE-2016-2106 CVE-2016-2107 CVE-2016-2108 mingw-openssl: various flaws [epel-7]
bugzilla·2016-05-03·CVSS 7.5
CVE-2016-2105 [HIGH] CVE-2016-2105 CVE-2016-2106 CVE-2016-2107 CVE-2016-2108 mingw-openssl: various flaws [epel-7]
CVE-2016-2105 CVE-2016-2106 CVE-2016-2107 CVE-2016-2108 mingw-openssl: various flaws [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
[bug automatically created by: add-
Bugzilla
CVE-2016-2105 CVE-2016-2106 CVE-2016-2107 CVE-2016-2108 openssl: various flaws [fedora-all]
bugzilla·2016-05-03·CVSS 7.5
CVE-2016-2105 [HIGH] CVE-2016-2105 CVE-2016-2106 CVE-2016-2107 CVE-2016-2108 openssl: various flaws [fedora-all]
CVE-2016-2105 CVE-2016-2106 CVE-2016-2107 CVE-2016-2108 openssl: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supporte
Bugzilla
CVE-2016-2105 CVE-2016-2106 CVE-2016-2107 CVE-2016-2108 mingw-openssl: various flaws [fedora-all]
bugzilla·2016-05-03·CVSS 7.5
CVE-2016-2105 [HIGH] CVE-2016-2105 CVE-2016-2106 CVE-2016-2107 CVE-2016-2108 mingw-openssl: various flaws [fedora-all]
CVE-2016-2105 CVE-2016-2106 CVE-2016-2107 CVE-2016-2108 mingw-openssl: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple su
Bugzilla
CVE-2016-2105 CVE-2016-2106 CVE-2016-2107 CVE-2016-2108 openssl101e: various flaws [epel-5]
bugzilla·2016-05-03·CVSS 7.5
CVE-2016-2105 [HIGH] CVE-2016-2105 CVE-2016-2106 CVE-2016-2107 CVE-2016-2108 openssl101e: various flaws [epel-5]
CVE-2016-2105 CVE-2016-2106 CVE-2016-2107 CVE-2016-2108 openssl101e: various flaws [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
[bug automatically created by: add-tr
Bugzilla
CVE-2016-2107 openssl: Padding oracle in AES-NI CBC MAC check
bugzilla·2016-04-28·CVSS 2.6
CVE-2016-2107 [LOW] CVE-2016-2107 openssl: Padding oracle in AES-NI CBC MAC check
CVE-2016-2107 openssl: Padding oracle in AES-NI CBC MAC check
Quoting form the draft of OpenSSL upstream advisory:
Padding oracle in AES-NI CBC MAC check (CVE-2016-2107)
Severity: High
A MITM attacker can use a padding oracle attack to decrypt traffic
when the connection uses an AES CBC cipher and the server support
AES-NI.
This issue was introduced as part of the fix for Lucky 13 padding
attack (CVE-2013-0169). The padding check was rewritten to be in
constant time by making sure that always the same bytes are read and
compared against either the MAC or padding bytes. But it no longer
checked that there was enough data to have both the MAC and padding
bytes.
OpenSSL 1.0.2 users should upgrade to 1.0.2h
OpenSSL 1.0.1 users should upgrade to 1.0.1t
This issue was reported to OpenSSL
Tenable
[R5] OpenSSL '20160503' Advisory Affects Tenable Products
blogs_tenable·2016-05-18
[R5] OpenSSL '20160503' Advisory Affects Tenable Products
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Qualys
OpenSSL CVE-2016-2107 Grading Update | Qualys
blogs_qualys·2016-05-10·CVSS 5.9
CVE-2016-2107 [MEDIUM] OpenSSL CVE-2016-2107 Grading Update | Qualys
We are releasing an update to the grading criteria, version 2009m, to respond to the discovery of the OpenSSL vulnerability CVE-2016-2107 announced in the OpenSSL Security Advisory [3rd May 2016]. This vulnerability can be exploited by MITM attacker using a padding Oracle attack to decrypt traffic when the connection uses an AES CBC cipher and the server supports AES-NI.
We are giving advance notification for the grading criteria changes. Currently, if the server is found to be vulnerable to this attack, grades are capped at C. Grades will be capped at F from June 6, 2016.
### Related
Qualys
OpenSSL CVE-2016-2107 Grading Update | Qualys
blogs_qualys·2016-05-09·CVSS 5.9
CVE-2016-2107 [MEDIUM] OpenSSL CVE-2016-2107 Grading Update | Qualys
We are releasing an update to the grading criteria, version 2009m, to respond to the discovery of the OpenSSL vulnerability CVE-2016-2107 announced in the OpenSSL Security Advisory [3rd May 2016]. This vulnerability can be exploited by MITM attacker using a padding Oracle attack to decrypt traffic when the connection uses an AES CBC cipher and the server supports AES-NI.
We are giving advance notification for the grading criteria changes. Currently, if the server is found to be vulnerable to this attack, grades are capped at C. Grades will be capped at F from June 6, 2016.
## Related content
arXiv
How vulnerable are the Indian banks: A cryptographers' view
arxiv_fulltext·2018-04-11
How vulnerable are the Indian banks: A cryptographers' view
How vulnerable are the Indian banks: A cryptographers' view
center
Anirban Pathak^ , (email: [email protected]),
Rishi Dutt Sharma^ , (email: [email protected]), Dhananjoy
Dey^ , (email: [email protected])
^ Jaypee Institute of Information Technology, A 10, Sector 62,
Noida, UP-201309, India
^ Department of Computer Science Engineering, Bennett University,
Greater Noida, UP-201310, India
^ Scientific Analysis Group, Metcalfe House Complex, Delhi-110
054, INDIA
## Abstract
With the advent of e-commerce and online banking it has become extremely
important that the websites of the financial institutes (especially,
banks) implement up-to-date measures of cyber security (in accordance
with the recommendations of the regulatory authority) and thus circumvent
the possibiliti
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10759http://lists.apple.com/archives/security-announce/2016/Jul/msg00000.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-May/183457.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-May/183607.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-May/184605.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00016.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00019.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00019.htmlhttp://packetstormsecurity.com/files/136912/Slackware-Security-Advisory-openssl-Updates.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0722.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0996.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2073.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2957.htmlhttp://source.android.com/security/bulletin/2016-07-01.htmlhttp://support.citrix.com/article/CTX212736http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160504-opensslhttp://web-in-security.blogspot.ca/2016/05/curious-padding-oracle-in-openssl-cve.htmlhttp://www.debian.org/security/2016/dsa-3566http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlhttp://www.securityfocus.com/bid/89760http://www.securityfocus.com/bid/91787http://www.securitytracker.com/id/1035721http://www.slackware.com/security/viewer.php?l=slackware-security&y=2016&m=slackware-security.542103http://www.ubuntu.com/usn/USN-2959-1https://blog.cloudflare.com/yet-another-padding-oracle-in-openssl-cbc-ciphersuites/https://bto.bluecoat.com/security-advisory/sa123https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdfhttps://git.openssl.org/?p=openssl.git%3Ba=commit%3Bh=68595c0c2886e7942a14f98c17a55a88afb6c292https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbgn03726en_ushttps://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbgn03728en_ushttps://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03756en_ushttps://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03765en_ushttps://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05164862https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05320149https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05386804https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA40202https://kc.mcafee.com/corporate/index?page=content&id=SB10160https://security.gentoo.org/glsa/201612-16https://security.netapp.com/advisory/ntap-20160504-0001/https://support.apple.com/HT206903https://www.exploit-db.com/exploits/39768/https://www.freebsd.org/security/advisories/FreeBSD-SA-16:17.openssl.aschttps://www.openssl.org/news/secadv/20160503.txthttps://www.tenable.com/security/tns-2016-18http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10759http://lists.apple.com/archives/security-announce/2016/Jul/msg00000.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-May/183457.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-May/183607.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-May/184605.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00013.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00014.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00016.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00019.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00019.htmlhttp://packetstormsecurity.com/files/136912/Slackware-Security-Advisory-openssl-Updates.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0722.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0996.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2073.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2957.htmlhttp://source.android.com/security/bulletin/2016-07-01.htmlhttp://support.citrix.com/article/CTX212736http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160504-opensslhttp://web-in-security.blogspot.ca/2016/05/curious-padding-oracle-in-openssl-cve.htmlhttp://www.debian.org/security/2016/dsa-3566http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlhttp://www.securityfocus.com/bid/89760http://www.securityfocus.com/bid/91787http://www.securitytracker.com/id/1035721http://www.slackware.com/security/viewer.php?l=slackware-security&y=2016&m=slackware-security.542103http://www.ubuntu.com/usn/USN-2959-1https://blog.cloudflare.com/yet-another-padding-oracle-in-openssl-cbc-ciphersuites/https://bto.bluecoat.com/security-advisory/sa123https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdfhttps://git.openssl.org/?p=openssl.git%3Ba=commit%3Bh=68595c0c2886e7942a14f98c17a55a88afb6c292https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbgn03726en_us
+ 16 more references
2016-05-05
Published