CVE-2016-0701 describes a vulnerability in OpenSSL versions 1.0.2 before 1.0.2f, where the DH_check_pub_key function fails to properly validate prime numbers used in Diffie-Hellman key exchange. This flaw allows a remote attacker, with high attack complexity, to potentially discover a private DH exponent through multiple handshakes, leading to a low confidentiality impact (CVSS 3.7 Low). While no public exploit code is available and it is not listed in CISA's Known Exploited Vulnerabilities catalog, the CVE is on the "Hot List" and has garnered significant community discussion and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.2CPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.2:*:*:*:*:*:*:* | ||
1.0.2CPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.2:beta1:*:*:*:*:*:* | ||
1.0.2CPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.2:beta2:*:*:*:*:*:* | ||
1.0.2CPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.2:beta3:*:*:*:*:*:* | ||
1.0.2aCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.2a:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.