CVE-2016-7054

HIGH

Openssl - Improper Access Control

Title source: rule
STIX 2.1

Description

In OpenSSL 1.1.0 before 1.1.0c, TLS connections using *-CHACHA20-POLY1305 ciphersuites are susceptible to a DoS attack by corrupting larger payloads. This can result in an OpenSSL crash. This issue is not considered to be exploitable beyond a DoS.

Exploits (1)

exploitdb WORKING POC
by Silverfox · pythondoslinux
https://www.exploit-db.com/exploits/40899

Scores

CVSS v3 7.5
EPSS 0.2094
EPSS Percentile 95.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-284
Status published
Products (6)
openssl/openssl 1.1.0
openssl/openssl 1.1.0a
openssl/openssl 1.1.0b
OpenSSL/OpenSSL openssl-1.1.0
OpenSSL/OpenSSL openssl-1.1.0a
OpenSSL/OpenSSL openssl-1.1.0b
Published May 04, 2017
Tracked Since Feb 18, 2026