ZeroHour

CVE-2016-2461

CVSS 3.0
7.0 high
EPSS
<1%p38
Published
()
Modified
Description

OpenSSLCipher.java in Conscrypt in Android 6.x before 2016-05-01 mishandles resets of the Additional Authenticated Data (AAD) array, which allows attackers to spoof message authentication via unspecified vectors, aka internal bugs 27324690 and 27696681.

Vendors
google
Products
android
Weakness
CWE-264
Vector
CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.