Severity
7.5HIGH
EPSS
23.0%
top 4.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 16
Latest updateMay 13

Description

The Anti-Replay feature in the DTLS implementation in OpenSSL before 1.1.0 mishandles early use of a new epoch number in conjunction with a large sequence number, which allows remote attackers to cause a denial of service (false-positive packet drops) via spoofed DTLS records, related to rec_layer_d1.c and ssl3_record.c.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

Debianopenssl< 1.0.2i-1+3
NVDopenssl/openssl30 versions+29
NVDoracle/linux6, 7+1

🔴Vulnerability Details

3
GHSA
GHSA-mpfh-46p6-w5g3: The Anti-Replay feature in the DTLS implementation in OpenSSL before 12022-05-13
OSV
CVE-2016-2181: The Anti-Replay feature in the DTLS implementation in OpenSSL before 12016-09-16
CVEList
CVE-2016-2181: The Anti-Replay feature in the DTLS implementation in OpenSSL before 12016-09-16

📋Vendor Advisories

5
Cisco
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 20162016-09-27
BSD
FreeBSD-SA-16:26.openssl: Multiple OpenSSL vulnerabilities2016-09-23
Ubuntu
OpenSSL vulnerabilities2016-09-22
Red Hat
openssl: DTLS replay protection bypass allows DoS against DTLS connection2016-07-05
Debian
CVE-2016-2181: openssl - The Anti-Replay feature in the DTLS implementation in OpenSSL before 1.1.0 misha...2016

💬Community

5
Bugzilla
CVE-2016-2181 mingw-openssl: openssl: DTLS replay protection bypass via sending large sequence number [fedora-all]2016-08-22
Bugzilla
CVE-2016-2181 openssl: DTLS replay protection bypass allows DoS against DTLS connection2016-08-22
Bugzilla
CVE-2016-2181 openssl: DTLS replay protection bypass via sending large sequence number [fedora-all]2016-08-22
Bugzilla
CVE-2016-2181 openssl101e: openssl: DTLS replay protection bypass via sending large sequence number [epel-5]2016-08-22
Bugzilla
CVE-2015-2181 CVE-2015-8864 CVE-2016-4068 CVE-2016-4069 roundcubemail: security issues fixed in version 1.0.92016-04-25
CVE-2016-2181 (HIGH CVSS 7.5) | The Anti-Replay feature in the DTLS | cvebase.io