← All CVEs

CVE-2016-2181

high · 7.5

The Anti-Replay feature in the DTLS implementation in OpenSSL before 1.1.0 mishandles early use of a new epoch number in conjunction with a large sequence number, which allows remote attackers to cause a denial of service (false-positive packet drops) via spoofed DTLS records, related to rec_layer_d1.c and ssl3_record.c.

7.5
CVSS
22.6%
EPSS (exploit prob.)
98th
EPSS percentile
2016-09-16
Published

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses

CWE-189

Affected products

VendorProductAffected versions
opensslopenssl1.0.1
opensslopenssl1.0.1a
opensslopenssl1.0.1b
opensslopenssl1.0.1c
opensslopenssl1.0.1d
opensslopenssl1.0.1e
opensslopenssl1.0.1f
opensslopenssl1.0.1g
opensslopenssl1.0.1h
opensslopenssl1.0.1i
opensslopenssl1.0.1j
opensslopenssl1.0.1k
opensslopenssl1.0.1l
opensslopenssl1.0.1m
opensslopenssl1.0.1n
opensslopenssl1.0.1o
opensslopenssl1.0.1p
opensslopenssl1.0.1q
opensslopenssl1.0.1r
opensslopenssl1.0.1s
opensslopenssl1.0.1t
opensslopenssl1.0.2
opensslopenssl1.0.2a
opensslopenssl1.0.2b
opensslopenssl1.0.2c
opensslopenssl1.0.2d
opensslopenssl1.0.2e
opensslopenssl1.0.2f
opensslopenssl1.0.2g
opensslopenssl1.0.2h
oraclelinux6
oraclelinux7

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2016-2181