CVE-2012-2686
OpenSSL 1.0.1 - Denial of Service via Crafted CBC Data in AES-NI
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2012-2686.
Includes Metasploit module auxiliary/dos/ssl/openssl_aesni.
AI-analyzed exploit summary This Metasploit module exploits CVE-2012-2686, an integer underflow in OpenSSL's AES-NI implementation for TLS 1.1/1.2, causing a DoS. It crafts malformed TLS handshake packets to trigger the vulnerability in 64-bit OpenSSL 1.0.1c.
Description
crypto/evp/e_aes_cbc_hmac_sha1.c in the AES-NI functionality in the TLS 1.1 and 1.2 implementations in OpenSSL 1.0.1 before 1.0.1d allows remote attackers to cause a denial of service (application crash) via crafted CBC data.
Exploits (1)
This Metasploit module exploits CVE-2012-2686, an integer underflow in OpenSSL's AES-NI implementation for TLS 1.1/1.2, causing a DoS. It crafts malformed TLS handshake packets to trigger the vulnerability in 64-bit OpenSSL 1.0.1c.