CVE-2016-8610
A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote attacker could use this flaw to make a TLS/SSL server consume an excessive amount of CPU and fail to accept connections from other clients.
Published:Oct 24, 2016
Last Modified:Apr 20, 2025
EPS:Nov 13, 2017
EPSS Score:0.71829
CVSS Score:7.5
Affected Products
Vendor
Product
Action
Vendor
Debian
Product
Debian Linux
Debian
Debian Linux
Vendor
Fujitsu
Product
M10-1
Fujitsu
M10-1
Vendor
Fujitsu
Product
M10-1 Firmware
Fujitsu
M10-1 Firmware
Vendor
Fujitsu
Product
M10-4
Fujitsu
M10-4
Vendor
Fujitsu
Product
M10-4 Firmware
Fujitsu
M10-4 Firmware
Vendor
Fujitsu
Product
M10-4s
Fujitsu
M10-4s
Vendor
Fujitsu
Product
M10-4s Firmware
Fujitsu
M10-4s Firmware
Vendor
Fujitsu
Product
M12-1
Fujitsu
M12-1
Vendor
Fujitsu
Product
M12-1 Firmware
Fujitsu
M12-1 Firmware
Vendor
Fujitsu
Product
M12-2
Fujitsu
M12-2
Vendor
Fujitsu
Product
M12-2 Firmware
Fujitsu
M12-2 Firmware
Vendor
Fujitsu
Product
M12-2s
Fujitsu
M12-2s
Vendor
Fujitsu
Product
M12-2s Firmware
Fujitsu
M12-2s Firmware
Vendor
Netapp
Product
Clustered Data Ontap
Netapp
Clustered Data Ontap
Vendor
Netapp
Product
Clustered Data Ontap Antivirus Connector
Netapp
Clustered Data Ontap Antivirus Connector
Vendor
Netapp
Product
Cn1610
Netapp
Cn1610
Vendor
Netapp
Product
Cn1610 Firmware
Netapp
Cn1610 Firmware
Vendor
Netapp
Product
Data Ontap
Netapp
Data Ontap
Vendor
Netapp
Product
Data Ontap Edge
Netapp
Data Ontap Edge
Vendor
Netapp
Product
E-series Santricity Os Controller
Netapp
E-series Santricity Os Controller
Vendor
Netapp
Product
Host Agent
Netapp
Host Agent
Vendor
Netapp
Product
Oncommand Balance
Netapp
Oncommand Balance
Vendor
Netapp
Product
Oncommand Unified Manager
Netapp
Oncommand Unified Manager
Vendor
Netapp
Product
Oncommand Workflow Automation
Netapp
Oncommand Workflow Automation
Vendor
Netapp
Product
Ontap Select Deploy
Netapp
Ontap Select Deploy
Vendor
Netapp
Product
Service Processor
Netapp
Service Processor
Vendor
Netapp
Product
Smi-s Provider
Netapp
Smi-s Provider
Vendor
Netapp
Product
Snapcenter Server
Netapp
Snapcenter Server
Vendor
Netapp
Product
Snapdrive
Netapp
Snapdrive
Vendor
Netapp
Product
Storagegrid
Netapp
Storagegrid
Vendor
Netapp
Product
Storagegrid Webscale
Netapp
Storagegrid Webscale
Vendor
Openssl
Product
Openssl
Openssl
Openssl
Vendor
Oracle
Product
Adaptive Access Manager
Oracle
Adaptive Access Manager
Vendor
Oracle
Product
Application Testing Suite
Oracle
Application Testing Suite
Vendor
Oracle
Product
Communications Analytics
Oracle
Communications Analytics
Vendor
Oracle
Product
Communications Ip Service Activator
Oracle
Communications Ip Service Activator
Vendor
Oracle
Product
Core Rdbms
Oracle
Core Rdbms
Vendor
Oracle
Product
Enterprise Manager Ops Center
Oracle
Enterprise Manager Ops Center
Vendor
Oracle
Product
Goldengate Application Adapters
Oracle
Goldengate Application Adapters
Vendor
Oracle
Product
Jd Edwards Enterpriseone Tools
Oracle
Jd Edwards Enterpriseone Tools
Vendor
Oracle
Product
Peoplesoft Enterprise Peopletools
Oracle
Peoplesoft Enterprise Peopletools
Vendor
Oracle
Product
Retail Predictive Application Server
Oracle
Retail Predictive Application Server
Vendor
Oracle
Product
Timesten In-memory Database
Oracle
Timesten In-memory Database
Vendor
Oracle
Product
Weblogic Server
Oracle
Weblogic Server
Vendor
Paloaltonetworks
Product
Pan-os
Paloaltonetworks
Pan-os
Vendor
Redhat
Product
Enterprise Linux
Redhat
Enterprise Linux
Vendor
Redhat
Product
Enterprise Linux Desktop
Redhat
Enterprise Linux Desktop
Vendor
Redhat
Product
Enterprise Linux Server
Redhat
Enterprise Linux Server
Vendor
Redhat
Product
Enterprise Linux Server Aus
Redhat
Enterprise Linux Server Aus
Vendor
Redhat
Product
Enterprise Linux Server Eus
Redhat
Enterprise Linux Server Eus
Vendor
Redhat
Product
Enterprise Linux Server Tus
Redhat
Enterprise Linux Server Tus
Vendor
Redhat
Product
Enterprise Linux Workstation
Redhat
Enterprise Linux Workstation
Vendor
Redhat
Product
Jboss Core Services
Redhat
Jboss Core Services
Vendor
Redhat
Product
Jboss Enterprise Application Platform
Redhat
Jboss Enterprise Application Platform
Vendor
Redhat
Product
Jboss Enterprise Web Server
Redhat
Jboss Enterprise Web Server
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
