Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2016-8610


A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote attacker could use this flaw to make a TLS/SSL server consume an excessive amount of CPU and fail to accept connections from other clients.


Published

2017-11-13T22:29:00.203

Last Modified

2025-04-20T01:37:25.860

Status

Deferred

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-400
  • Type: Secondary
    CWE-400

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application openssl openssl ≤ 1.0.2h Yes
Application openssl openssl 0.9.8 Yes
Application openssl openssl 1.0.1 Yes
Application openssl openssl 1.1.0 Yes
Operating System debian debian_linux 8.0 Yes
Operating System redhat enterprise_linux_desktop 6.0 Yes
Operating System redhat enterprise_linux_desktop 7.0 Yes
Operating System redhat enterprise_linux_server 6.0 Yes
Operating System redhat enterprise_linux_server 7.0 Yes
Operating System redhat enterprise_linux_server_aus 7.3 Yes
Operating System redhat enterprise_linux_server_aus 7.4 Yes
Operating System redhat enterprise_linux_server_aus 7.6 Yes
Operating System redhat enterprise_linux_server_eus 7.3 Yes
Operating System redhat enterprise_linux_server_eus 7.4 Yes
Operating System redhat enterprise_linux_server_eus 7.5 Yes
Operating System redhat enterprise_linux_server_eus 7.6 Yes
Operating System redhat enterprise_linux_server_tus 7.3 Yes
Operating System redhat enterprise_linux_server_tus 7.6 Yes
Operating System redhat enterprise_linux_workstation 6.0 Yes
Operating System redhat enterprise_linux_workstation 7.0 Yes
Application redhat jboss_enterprise_application_platform 6.0.0 Yes
Application redhat jboss_enterprise_application_platform 6.4.0 Yes
Operating System redhat enterprise_linux 6.0 No
Operating System redhat enterprise_linux 7.0 No
Operating System netapp cn1610_firmware - Yes
Hardware netapp cn1610 - No
Application netapp clustered_data_ontap_antivirus_connector - Yes
Application netapp data_ontap - Yes
Application netapp data_ontap_edge - Yes
Application netapp e-series_santricity_os_controller ≤ 11.40 Yes
Application netapp host_agent - Yes
Application netapp oncommand_balance - Yes
Application netapp oncommand_unified_manager - Yes
Application netapp oncommand_workflow_automation - Yes
Application netapp ontap_select_deploy - Yes
Application netapp service_processor - Yes
Application netapp smi-s_provider - Yes
Application netapp snapcenter_server - Yes
Application netapp snapdrive - Yes
Application netapp storagegrid - Yes
Application netapp storagegrid_webscale - Yes
Operating System netapp clustered_data_ontap - Yes
Operating System paloaltonetworks pan-os ≤ 6.1.17 Yes
Operating System paloaltonetworks pan-os ≤ 7.0.15 Yes
Operating System paloaltonetworks pan-os ≤ 7.1.10 Yes
Application oracle adaptive_access_manager 11.1.2.3.0 Yes
Application oracle application_testing_suite 13.3.0.1 Yes
Application oracle communications_analytics 12.1.1 Yes
Application oracle communications_ip_service_activator 7.3.4 Yes
Application oracle communications_ip_service_activator 7.4.0 Yes
Application oracle core_rdbms 11.2.0.4 Yes
Application oracle core_rdbms 12.1.0.2 Yes
Application oracle core_rdbms 12.2.0.1 Yes
Application oracle core_rdbms 18c Yes
Application oracle core_rdbms 19c Yes
Application oracle enterprise_manager_ops_center 12.3.3 Yes
Application oracle enterprise_manager_ops_center 12.4.0 Yes
Application oracle goldengate_application_adapters 12.3.2.1.0 Yes
Application oracle jd_edwards_enterpriseone_tools 9.2 Yes
Application oracle peoplesoft_enterprise_peopletools 8.56 Yes
Application oracle peoplesoft_enterprise_peopletools 8.57 Yes
Application oracle peoplesoft_enterprise_peopletools 8.58 Yes
Application oracle retail_predictive_application_server 15.0.3 Yes
Application oracle retail_predictive_application_server 16.0.3 Yes
Application oracle timesten_in-memory_database < 18.1.4.1.0 Yes
Application oracle weblogic_server 10.3.6.0.0 Yes
Application oracle weblogic_server 12.1.3.0.0 Yes
Application oracle weblogic_server 12.2.1.3.0 Yes
Application oracle weblogic_server 12.2.1.4.0 Yes
Operating System fujitsu m10-1_firmware < xcp2361 Yes
Operating System fujitsu m10-1_firmware < xcp3070 Yes
Hardware fujitsu m10-1 - No
Operating System fujitsu m10-4_firmware < xcp2361 Yes
Operating System fujitsu m10-4_firmware < xcp3070 Yes
Hardware fujitsu m10-4 - No
Operating System fujitsu m10-4s_firmware < xcp2361 Yes
Operating System fujitsu m10-4s_firmware < xcp3070 Yes
Hardware fujitsu m10-4s - No
Operating System fujitsu m12-1_firmware < xcp2361 Yes
Operating System fujitsu m12-1_firmware < xcp3070 Yes
Hardware fujitsu m12-1 - No
Operating System fujitsu m12-2_firmware < xcp2361 Yes
Operating System fujitsu m12-2_firmware < xcp3070 Yes
Hardware fujitsu m12-2 - No
Operating System fujitsu m12-2s_firmware < xcp2361 Yes
Operating System fujitsu m12-2s_firmware < xcp3070 Yes
Hardware fujitsu m12-2s - No

References