CVE-2016-6891 describes an out-of-bounds read vulnerability in MatrixSSL versions prior to 3.8.6, specifically affecting the handling of crafted ASN.1 Bit Field primitives within X.509 certificates. This vulnerability carries a high CVSS v3 score of 7.5, indicating it can be exploited remotely with low attack complexity, requiring no user interaction, and leading to a denial of service. While no public exploit code or active exploitation is reported, the vulnerability has garnered some community discussion and media coverage, highlighting its potential impact on IoT devices.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.8.5CPE matchmatch criteria | cpe:2.3:a:matrixssl:matrixssl:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.