ZeroHour

CVE-2016-8610

CVSS 3.1
7.5 high
EPSS
40%p99
Published
()
Modified
Description

A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote attacker could use this flaw to make a TLS/SSL server consume an excessive amount of CPU and fail to accept connections from other clients.

Vendors
openssldebianredhatnetapppaloaltonetworksoraclefujitsu
Products
openssl, debian linux, enterprise linux desktop, enterprise linux server, enterprise linux server aus, enterprise linux server eus, enterprise linux server tus, enterprise linux workstation, jboss enterprise application platform, cn1610 firmware, clustered data ontap antivirus connector, data ontap
Weakness
CWE-400
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.