Record summary

CVE-2012-2686 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.

Description

crypto/evp/e_aes_cbc_hmac_sha1.c in the AES-NI functionality in the TLS 1.1 and 1.2 implementations in OpenSSL 1.0.1 before 1.0.1d allows remote attackers to cause a denial of service (application crash) via crafted CBC data.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

MetasploitOpenSSL TLS 1.1 and 1.2 AES-NI DoSMetasploit auxiliary PoCby Wolfgang Ettlinger <wolfgang.ettlinger@gmail.com>Not analyzed1 file

Ruby

Metasploit

PoC details

References

Showing 12 of 14