← All CVEs

CVE-2016-8610

high · 7.5

A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote attacker could use this flaw to make a TLS/SSL server consume an excessive amount of CPU and fail to accept connections from other clients.

7.5
CVSS
39.7%
EPSS (exploit prob.)
99th
EPSS percentile
2017-11-13
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses

CWE-400

Affected products

VendorProductAffected versions
opensslopenssl>= 1.0.2, <= 1.0.2h
opensslopenssl0.9.8
opensslopenssl1.0.1
opensslopenssl1.1.0
debiandebian_linux8.0
redhatenterprise_linux_desktop6.0
redhatenterprise_linux_desktop7.0
redhatenterprise_linux_server6.0
redhatenterprise_linux_server7.0
redhatenterprise_linux_server_aus7.3
redhatenterprise_linux_server_aus7.4
redhatenterprise_linux_server_aus7.6
redhatenterprise_linux_server_eus7.3
redhatenterprise_linux_server_eus7.4
redhatenterprise_linux_server_eus7.5
redhatenterprise_linux_server_eus7.6
redhatenterprise_linux_server_tus7.3
redhatenterprise_linux_server_tus7.6
redhatenterprise_linux_workstation6.0
redhatenterprise_linux_workstation7.0
redhatjboss_enterprise_application_platform6.0.0
redhatjboss_enterprise_application_platform6.4.0
redhatenterprise_linux6.0
redhatenterprise_linux7.0
netappcn1610_firmwareall versions
netappcn1610all versions
netappclustered_data_ontap_antivirus_connectorall versions
netappdata_ontapall versions
netappdata_ontap_edgeall versions
netappe-series_santricity_os_controller>= 11.0, <= 11.40
netapphost_agentall versions
netapponcommand_balanceall versions
netapponcommand_unified_managerall versions
netapponcommand_workflow_automationall versions
netappontap_select_deployall versions
netappservice_processorall versions
netappsmi-s_providerall versions
netappsnapcenter_serverall versions
netappsnapdriveall versions
netappstoragegridall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2016-8610