CVE-2016-8610

Published: Nov 13, 2017 Last Modified: Apr 20, 2025
ExploitDB:
Other exploit source:
Google Dorks:
HIGH 7,5
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: none
Availability: high
MEDIUM 5,0
Access Vector: network
Access Complexity: low
Authentication: none
Confidentiality: none
Integrity: none
Availability: partial

Description

AI Translation Available

A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote attacker could use this flaw to make a TLS/SSL server consume an excessive amount of CPU and fail to accept connections from other clients.

EPSS (Exploit Prediction Scoring System)

Trend Analysis

EPSS (Exploit Prediction Scoring System)

Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.

EPSS Score
0,7113
Percentile
1,0th
Updated

EPSS Score Trend (Last 90 Days)

400

Uncontrolled Resource Consumption

Draft
Common Consequences
Security Scopes Affected:
Availability Access Control Other
Potential Impacts:
Dos: Crash, Exit, Or Restart Dos: Resource Consumption (Cpu) Dos: Resource Consumption (Memory) Dos: Resource Consumption (Other) Bypass Protection Mechanism Other
Applicable Platforms
All platforms may be affected
View CWE Details
Application

Openssl by Openssl

Version Range Affected
From 1.0.2 (inclusive)
To 1.0.2h (inclusive)
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Service Processor by Netapp

cpe:2.3:a:netapp:service_processor:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Pan-Os by Paloaltonetworks

Version Range Affected
From 7.1.0 (inclusive)
To 7.1.10 (inclusive)
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Clustered Data Ontap by Netapp

cpe:2.3:o:netapp:clustered_data_ontap:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Retail Predictive Application Server by Oracle

cpe:2.3:a:oracle:retail_predictive_application_server:15.0.3:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Enterprise Linux Server Tus by Redhat

cpe:2.3:o:redhat:enterprise_linux_server_tus:7.3:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

M10-1 Firmware by Fujitsu

Version Range Affected
To xcp2361 (exclusive)
cpe:2.3:o:fujitsu:m10-1_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Pan-Os by Paloaltonetworks

Version Range Affected
From 7.0.0 (inclusive)
To 7.0.15 (inclusive)
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Openssl by Openssl

cpe:2.3:a:openssl:openssl:1.0.1:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

M12-1 Firmware by Fujitsu

Version Range Affected
To xcp2361 (exclusive)
cpe:2.3:o:fujitsu:m12-1_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Enterprise Linux Desktop by Redhat

cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Enterprise Manager Ops Center by Oracle

cpe:2.3:a:oracle:enterprise_manager_ops_center:12.4.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Oncommand Unified Manager by Netapp

cpe:2.3:a:netapp:oncommand_unified_manager:-:*:*:*:*:7-mode:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Core Rdbms by Oracle

cpe:2.3:a:oracle:core_rdbms:12.2.0.1:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Jd Edwards Enterpriseone Tools by Oracle

cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:9.2:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

M10-4 Firmware by Fujitsu

Version Range Affected
To xcp2361 (exclusive)
cpe:2.3:o:fujitsu:m10-4_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Pan-Os by Paloaltonetworks

Version Range Affected
To 6.1.17 (inclusive)
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

M10-4S Firmware by Fujitsu

Version Range Affected
To xcp2361 (exclusive)
cpe:2.3:o:fujitsu:m10-4s_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Weblogic Server by Oracle

cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Smi-S Provider by Netapp

cpe:2.3:a:netapp:smi-s_provider:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Retail Predictive Application Server by Oracle

cpe:2.3:a:oracle:retail_predictive_application_server:16.0.3:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Enterprise Linux Server by Redhat

cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Adaptive Access Manager by Oracle

cpe:2.3:a:oracle:adaptive_access_manager:11.1.2.3.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Host Agent by Netapp

cpe:2.3:a:netapp:host_agent:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Communications Analytics by Oracle

cpe:2.3:a:oracle:communications_analytics:12.1.1:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Oncommand Workflow Automation by Netapp

cpe:2.3:a:netapp:oncommand_workflow_automation:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Snapdrive by Netapp

cpe:2.3:a:netapp:snapdrive:-:*:*:*:*:unix:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Clustered Data Ontap Antivirus Connector by Netapp

cpe:2.3:a:netapp:clustered_data_ontap_antivirus_connector:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

M10-4S Firmware by Fujitsu

Version Range Affected
From xcp3000 (inclusive)
To xcp3070 (exclusive)
cpe:2.3:o:fujitsu:m10-4s_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

M12-2S Firmware by Fujitsu

Version Range Affected
To xcp2361 (exclusive)
cpe:2.3:o:fujitsu:m12-2s_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

M12-2 Firmware by Fujitsu

Version Range Affected
To xcp2361 (exclusive)
cpe:2.3:o:fujitsu:m12-2_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Data Ontap by Netapp

cpe:2.3:a:netapp:data_ontap:-:*:*:*:*:7-mode:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Openssl by Openssl

cpe:2.3:a:openssl:openssl:1.1.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

M12-2 Firmware by Fujitsu

Version Range Affected
From xcp3000 (inclusive)
To xcp3070 (exclusive)
cpe:2.3:o:fujitsu:m12-2_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Oncommand Balance by Netapp

cpe:2.3:a:netapp:oncommand_balance:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Core Rdbms by Oracle

cpe:2.3:a:oracle:core_rdbms:12.1.0.2:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Peoplesoft Enterprise Peopletools by Oracle

cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.57:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Ontap Select Deploy by Netapp

cpe:2.3:a:netapp:ontap_select_deploy:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Storagegrid Webscale by Netapp

cpe:2.3:a:netapp:storagegrid_webscale:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Enterprise Linux Workstation by Redhat

cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Openssl by Openssl

cpe:2.3:a:openssl:openssl:0.9.8:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Storagegrid by Netapp

cpe:2.3:a:netapp:storagegrid:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

M10-4 Firmware by Fujitsu

Version Range Affected
From xcp3000 (inclusive)
To xcp3070 (exclusive)
cpe:2.3:o:fujitsu:m10-4_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Enterprise Linux Server Aus by Redhat

cpe:2.3:o:redhat:enterprise_linux_server_aus:7.3:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Core Rdbms by Oracle

cpe:2.3:a:oracle:core_rdbms:19c:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Enterprise Linux Server by Redhat

cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

E-Series Santricity Os Controller by Netapp

Version Range Affected
From 11.0 (inclusive)
To 11.40 (inclusive)
cpe:2.3:a:netapp:e-series_santricity_os_controller:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Enterprise Linux Server Eus by Redhat

cpe:2.3:o:redhat:enterprise_linux_server_eus:7.4:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Application Testing Suite by Oracle

cpe:2.3:a:oracle:application_testing_suite:13.3.0.1:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Enterprise Linux Server Eus by Redhat

cpe:2.3:o:redhat:enterprise_linux_server_eus:7.5:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Timesten In-Memory Database by Oracle

Version Range Affected
To 18.1.4.1.0 (exclusive)
cpe:2.3:a:oracle:timesten_in-memory_database:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Enterprise Linux Server Eus by Redhat

cpe:2.3:o:redhat:enterprise_linux_server_eus:7.3:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Enterprise Manager Ops Center by Oracle

cpe:2.3:a:oracle:enterprise_manager_ops_center:12.3.3:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Jboss Enterprise Application Platform by Redhat

cpe:2.3:a:redhat:jboss_enterprise_application_platform:6.0.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Jboss Enterprise Application Platform by Redhat

cpe:2.3:a:redhat:jboss_enterprise_application_platform:6.4.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Enterprise Linux Server Aus by Redhat

cpe:2.3:o:redhat:enterprise_linux_server_aus:7.6:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Weblogic Server by Oracle

cpe:2.3:a:oracle:weblogic_server:10.3.6.0.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Enterprise Linux Server Tus by Redhat

cpe:2.3:o:redhat:enterprise_linux_server_tus:7.6:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Communications Ip Service Activator by Oracle

cpe:2.3:a:oracle:communications_ip_service_activator:7.3.4:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Enterprise Linux Server Eus by Redhat

cpe:2.3:o:redhat:enterprise_linux_server_eus:7.6:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Debian Linux by Debian

cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Weblogic Server by Oracle

cpe:2.3:a:oracle:weblogic_server:12.1.3.0.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Core Rdbms by Oracle

cpe:2.3:a:oracle:core_rdbms:18c:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Peoplesoft Enterprise Peopletools by Oracle

cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.56:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Enterprise Linux Server Aus by Redhat

cpe:2.3:o:redhat:enterprise_linux_server_aus:7.4:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Peoplesoft Enterprise Peopletools by Oracle

cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Communications Ip Service Activator by Oracle

cpe:2.3:a:oracle:communications_ip_service_activator:7.4.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Data Ontap Edge by Netapp

cpe:2.3:a:netapp:data_ontap_edge:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Core Rdbms by Oracle

cpe:2.3:a:oracle:core_rdbms:11.2.0.4:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Enterprise Linux Workstation by Redhat

cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Snapcenter Server by Netapp

cpe:2.3:a:netapp:snapcenter_server:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

M12-2S Firmware by Fujitsu

Version Range Affected
From xcp3000 (inclusive)
To xcp3070 (exclusive)
cpe:2.3:o:fujitsu:m12-2s_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Cn1610 Firmware by Netapp

cpe:2.3:o:netapp:cn1610_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Enterprise Linux Desktop by Redhat

cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

M10-1 Firmware by Fujitsu

Version Range Affected
From xcp3000 (inclusive)
To xcp3070 (exclusive)
cpe:2.3:o:fujitsu:m10-1_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Weblogic Server by Oracle

cpe:2.3:a:oracle:weblogic_server:12.2.1.3.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

M12-1 Firmware by Fujitsu

Version Range Affected
From xcp3000 (inclusive)
To xcp3070 (exclusive)
cpe:2.3:o:fujitsu:m12-1_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Goldengate Application Adapters by Oracle

cpe:2.3:a:oracle:goldengate_application_adapters:12.3.2.1.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
http://rhn.redhat.com/errata/RHSA-2017-0286.html
http://rhn.redhat.com/errata/RHSA-2017-0574.html
http://rhn.redhat.com/errata/RHSA-2017-1415.html
http://rhn.redhat.com/errata/RHSA-2017-1659.html
https://access.redhat.com/errata/RHSA-2017:1413
https://access.redhat.com/errata/RHSA-2017:1414
https://access.redhat.com/errata/RHSA-2017:1658
https://access.redhat.com/errata/RHSA-2017:1801
https://access.redhat.com/errata/RHSA-2017:1802
https://access.redhat.com/errata/RHSA-2017:2493
https://access.redhat.com/errata/RHSA-2017:2494
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8610
Issue Tracking Patch Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8610
http://seclists.org/oss-sec/2016/q4/224
Mailing List Third Party Advisory
http://seclists.org/oss-sec/2016/q4/224
https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commit%3Bh=af58be768ebb690f78…
https://security.360.cn/cve/CVE-2016-8610/
https://security.FreeBSD.org/advisories/FreeBSD-SA-16:35.openssl.asc
https://security.netapp.com/advisory/ntap-20171130-0001/
https://security.paloaltonetworks.com/CVE-2016-8610
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hp…
https://www.debian.org/security/2017/dsa-3773
https://www.oracle.com/security-alerts/cpuapr2020.html
https://www.oracle.com/security-alerts/cpujan2020.html
https://www.oracle.com/security-alerts/cpujul2020.html
https://www.oracle.com/security-alerts/cpuoct2020.html
https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
http://www.securityfocus.com/bid/93841
Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/93841
http://www.securitytracker.com/id/1037084
Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1037084
http://rhn.redhat.com/errata/RHSA-2017-0286.html
http://rhn.redhat.com/errata/RHSA-2017-0574.html
http://rhn.redhat.com/errata/RHSA-2017-1415.html
http://rhn.redhat.com/errata/RHSA-2017-1659.html
https://access.redhat.com/errata/RHSA-2017:1413
https://access.redhat.com/errata/RHSA-2017:1414
https://access.redhat.com/errata/RHSA-2017:1658
https://access.redhat.com/errata/RHSA-2017:1801
https://access.redhat.com/errata/RHSA-2017:1802
https://access.redhat.com/errata/RHSA-2017:2493
https://access.redhat.com/errata/RHSA-2017:2494
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8610
Issue Tracking Patch Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8610
http://seclists.org/oss-sec/2016/q4/224
Mailing List Third Party Advisory
http://seclists.org/oss-sec/2016/q4/224
https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commit%3Bh=af58be768ebb690f78…
https://security.360.cn/cve/CVE-2016-8610/
https://security.FreeBSD.org/advisories/FreeBSD-SA-16:35.openssl.asc
https://security.netapp.com/advisory/ntap-20171130-0001/
https://security.paloaltonetworks.com/CVE-2016-8610
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hp…
https://www.debian.org/security/2017/dsa-3773
https://www.oracle.com/security-alerts/cpuapr2020.html
https://www.oracle.com/security-alerts/cpujan2020.html
https://www.oracle.com/security-alerts/cpujul2020.html
https://www.oracle.com/security-alerts/cpuoct2020.html
https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
http://www.securityfocus.com/bid/93841
Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/93841
http://www.securitytracker.com/id/1037084
Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1037084