CVE-2016-0703 is a critical vulnerability in OpenSSL's SSLv2 implementation, affecting versions before 0.9.8zf, 1.0.0r, 1.0.1m, and 1.0.2a. This flaw allows man-in-the-middle attackers to decrypt TLS ciphertext by leveraging a Bleichenbacher RSA padding oracle, similar to CVE-2016-0800. With a CVSS score of 5.9 (Medium) and a high confidentiality impact, it requires high attack complexity but no user interaction. While there is no evidence of active exploitation or public exploit code, the vulnerability garnered significant media attention and community discussion at the time of its disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.9.8zeCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* | ||
1.0.0CPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.0:*:*:*:*:*:*:* | ||
1.0.0CPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.0:beta1:*:*:*:*:*:* | ||
1.0.0CPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.0:beta2:*:*:*:*:*:* | ||
1.0.0CPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.0:beta3:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.