CVE-2012-2686

OpenSSL 1.0.1 - Denial of Service via Crafted CBC Data in AES-NI

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2012-2686. Includes Metasploit module auxiliary/dos/ssl/openssl_aesni.

AI-analyzed exploit summary This Metasploit module exploits CVE-2012-2686, an integer underflow in OpenSSL's AES-NI implementation for TLS 1.1/1.2, causing a DoS. It crafts malformed TLS handshake packets to trigger the vulnerability in 64-bit OpenSSL 1.0.1c.

Description

crypto/evp/e_aes_cbc_hmac_sha1.c in the AES-NI functionality in the TLS 1.1 and 1.2 implementations in OpenSSL 1.0.1 before 1.0.1d allows remote attackers to cause a denial of service (application crash) via crafted CBC data.

Exploits (1)

metasploit WORKING POC
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/dos/ssl/openssl_aesni.rb

This Metasploit module exploits CVE-2012-2686, an integer underflow in OpenSSL's AES-NI implementation for TLS 1.1/1.2, causing a DoS. It crafts malformed TLS handshake packets to trigger the vulnerability in 64-bit OpenSSL 1.0.1c.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target: OpenSSL 1.0.1c (64-bit)
No auth needed
Prerequisites: Network access to target's TLS service (typically port 443)
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (12)

Core 12
Core References
Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2013/Sep/msg00002.html
Vendor Advisory x_refsource_confirm
http://www.openssl.org/news/secadv_20130204.txt
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18868
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=137545771702053&w=2
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=908029
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19660
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT5880
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/57755
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/55139
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/55108

Scores

EPSS 0.6314
EPSS Percentile 98.4%

Details

CWE
CWE-310
Status published
Products (4)
openssl/openssl 1.0.1
openssl/openssl 1.0.1a
openssl/openssl 1.0.1b
openssl/openssl 1.0.1c
Published Feb 08, 2013
Tracked Since Feb 18, 2026