CVE-2016-0800: OpenSSL
Medium severity, CVSS 5.9. EPSS: 82.1% chance of exploitation in the next 30 days.
The SSLv2 protocol, as used in OpenSSL before 1.0.1s and 1.0.2 before 1.0.2g and other products, requires a server to send a ServerVerify message before establishing that a client possesses certain plaintext RSA data, which makes it easier for remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a "DROWN" attack.
Affected products
- OpenSSL OpenSSL: version 1.0.1 only; version 1.0.1a only; version 1.0.1b only; version 1.0.1c only; version 1.0.1d only; version 1.0.1e only; …
- Pulse Secure Client: affected versions not specified
- Pulse Secure Steel Belted Radius: affected versions not specified
Published 2016-03-01. Last modified 2026-06-17.