CVE-2016-2462
published 2016-05-09CVE-2016-2462: OpenSSLCipher.java in Conscrypt in Android 6.x before 2016-05-01 mishandles updates of the Additional Authenticated Data (AAD) array, which allows attackers to…
PriorityP425high7CVSS 3.0
AVLACHPRNUIRSUCHIHAH
EPSS
0.39%
31.8th percentile
OpenSSLCipher.java in Conscrypt in Android 6.x before 2016-05-01 mishandles updates of the Additional Authenticated Data (AAD) array, which allows attackers to spoof message authentication via unspecified vectors, aka internal bug 27371173.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.07.0HIGHCVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2016-2462: Android Security Bulletin 2016-05-01
CVE: CVE-2016-2462
Severity: MEDIUM
Affected AOSP versions: 6
vendor_android·2016-05-01·CVSS 7.0
CVE-2016-2462 [HIGH] CVE-2016-2462: Android Security Bulletin 2016-05-01
CVE: CVE-2016-2462
Severity: MEDIUM
Affected AOSP versions: 6
Android Security Bulletin 2016-05-01
CVE: CVE-2016-2462
Severity: MEDIUM
Affected AOSP versions: 6.0, 6.0.1
GHSA
GHSA-c8h7-9j5h-vfp2: OpenSSLCipher
ghsa_unreviewed·2022-05-17
CVE-2016-2462 [HIGH] GHSA-c8h7-9j5h-vfp2: OpenSSLCipher
OpenSSLCipher.java in Conscrypt in Android 6.x before 2016-05-01 mishandles updates of the Additional Authenticated Data (AAD) array, which allows attackers to spoof message authentication via unspecified vectors, aka internal bug 27371173.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://source.android.com/security/bulletin/2016-05-01.htmlhttps://android.googlesource.com/platform/external/conscrypt/+/8bec47d2184fca7e8b7337d2a65b2b75a9bc8f54http://source.android.com/security/bulletin/2016-05-01.htmlhttps://android.googlesource.com/platform/external/conscrypt/+/8bec47d2184fca7e8b7337d2a65b2b75a9bc8f54
2016-05-09
Published