cbcvebase.
CVE-2016-7056
published 2018-09-10

CVE-2016-7056: A timing attack flaw was found in OpenSSL 1.0.1u and before that could allow a malicious user with local access to recover ECDSA P-256 private keys.

PriorityP424medium5.5CVSS 3.0
AVLACLPRLUINSUCHINAN
EPSS
0.59%
44.5th percentile
A timing attack flaw was found in OpenSSL 1.0.1u and before that could allow a malicious user with local access to recover ECDSA P-256 private keys.

Affected

17 ranges
VendorProductVersion rangeFixed in
applemacos_sierra_10.12.4_security_update_2017-001_el_capitan_and_security_update_201
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debianopenssl< openssl 1.0.2a-1 (bookworm)openssl 1.0.2a-1 (bookworm)
googleandroid
opensslopenssl<= 1.0.1u
opensslopenssl>= 0 < 1.0.2a-11.0.2a-1
opensslopenssl>= 0 < 1.0.2a-11.0.2a-1
opensslopenssl>= 0 < 1.0.2a-11.0.2a-1
opensslopenssl>= 0 < 1.0.2a-11.0.2a-1
opensslopenssl>= 0 < 1.0.1f-1ubuntu2.221.0.1f-1ubuntu2.22
opensslopenssl>= 0 < 1.0.2g-1ubuntu4.61.0.2g-1ubuntu4.6
redhatenterprise_linux
redhatenterprise_linux
the_openssl_projectopenssl

CVSS provenance

nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.