cbcvebase.
CVE-2016-8610
published 2017-11-13

CVE-2016-8610: A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets…

PriorityP353high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
39.66%
98.5th percentile
A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote attacker could use this flaw to make a TLS/SSL server consume an excessive amount of CPU and fail to accept connections from other clients.

Affected

73 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianopenssl< openssl 1.0.2j-1 (bookworm)openssl 1.0.2j-1 (bookworm)
fujitsum10-1_firmware< xcp2361xcp2361
fujitsum10-1_firmware>= xcp3000 < xcp3070xcp3070
fujitsum10-4_firmware< xcp2361xcp2361
fujitsum10-4_firmware>= xcp3000 < xcp3070xcp3070
fujitsum10-4s_firmware< xcp2361xcp2361
fujitsum10-4s_firmware>= xcp3000 < xcp3070xcp3070
fujitsum12-1_firmware< xcp2361xcp2361
fujitsum12-1_firmware>= xcp3000 < xcp3070xcp3070
fujitsum12-2_firmware< xcp2361xcp2361
fujitsum12-2_firmware>= xcp3000 < xcp3070xcp3070
fujitsum12-2s_firmware< xcp2361xcp2361
fujitsum12-2s_firmware>= xcp3000 < xcp3070xcp3070
netappe-series_santricity_os_controller11.0 – 11.40
opensslopenssl
opensslopenssl
opensslopenssl
opensslopenssl
opensslopenssl
opensslopenssl
opensslopenssl>= 0 < 1.0.2j-11.0.2j-1
opensslopenssl>= 0 < 1.0.2j-11.0.2j-1
opensslopenssl>= 0 < 1.0.2j-11.0.2j-1
opensslopenssl>= 0 < 1.0.2j-11.0.2j-1

Detection & IOCsextracted from sources · hover to see the quote

snort
1:40843
  • The attack involves sending a large volume of SSL ALERT packets during a TLS/SSL handshake to exhaust CPU on the target server. Detection should focus on abnormally high rates of TLS/SSL ALERT messages from a single source IP.
  • Snort rule 1:40843 can be used to detect and block exploitation of CVE-2016-8610 (SSL Death Alert DoS). Ensure this rule is enabled in your Snort default policy set.
  • The vulnerability is exploitable during the TLS/SSL connection handshake phase via malformed plain-text ALERT packets. Monitor for excessive CPU consumption on TLS-terminating services (e.g., Nginx) as a potential indicator of active exploitation.
  • ·Apache httpd is NOT affected by this issue; Nginx IS affected. Detection and mitigation efforts should be prioritized on Nginx and other applications compiled against OpenSSL or GnuTLS that do not allocate an extra thread for processing ClientHello messages.
  • ·Firewall-level mitigation is possible by rate-limiting connections per IP or using deep packet inspection to reject malicious ALERT packets, which can reduce exposure even on unpatched systems.
  • ·PAN-OS versions 6.1.17 and earlier, 7.0.15 and earlier, and 7.1.10 and earlier are affected. Ensure PAN-OS is updated to 6.1.18+, 7.0.16+, or 7.1.11+ respectively.

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.