CVE-2016-2107

medium HPE
CVSS v3 Base Score
5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
80.0%
Exploitation probability in 30 days
Top 1% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Confidentiality
High
Integrity
None
Availability
None
Published: May 5, 2016 (3662 days ago)
Last Modified: May 6, 2026
Vendor: HPE
Source: NVD

Description

The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obtain sensitive cleartext information via a padding-oracle attack against an AES CBC session. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-0169.

CWE

CWE-200

Affected Products

redhat enterprise linux desktopredhat enterprise linux hpc noderedhat enterprise linux hpc node eusredhat enterprise linux serverredhat enterprise linux server ausredhat enterprise linux server eusredhat enterprise linux workstationopensuse leapopensuse opensuseopenssl openssl

References