CVE-2016-2182: HP Icewall Federation Agent

Critical severity, CVSS 9.8. EPSS: 46.1% chance of exploitation in the next 30 days.

The BN_bn2dec function in crypto/bn/bn_print.c in OpenSSL before 1.1.0 does not properly validate division results, which allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly have unspecified other impact via unknown vectors.

Affected products

  • HP Icewall Federation Agent: version 3.0 only
  • HP Icewall Mcrp: version 3.0 only
  • HP Icewall SSO: version 10.0 only
  • HP Icewall SSO Agent Option: version 10.0 only
  • OpenSSL OpenSSL: version 1.0.1 only; version 1.0.1a only; version 1.0.1b only; version 1.0.1c only; version 1.0.1d only; version 1.0.1e only; …
  • Oracle Linux: version 5 only; version 6 only; version 7 only

Published 2016-09-16. Last modified 2026-06-17.