Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2016-7055

23
FAUCET Score

CVE-2016-7055 is a carry propagating bug in the Broadwell-specific Montgomery multiplication procedure within OpenSSL versions 1.0.2 and 1.1.0 before 1.1.0c, affecting products like Node.js that utilize these OpenSSL versions. The vulnerability can lead to transient authentication and key negotiation failures or erroneous public-key operations with specially crafted input, specifically impacting Brainpool P-512 curves in EC algorithms. Rated Medium with a CVSS score of 5.9 (AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H), it has a high attack complexity and can result in denial of service. While attacks against RSA, DSA, and DH private keys are deemed impossible, ECDH key negotiation could be vulnerable under specific, non-default conditions. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage are minimal, indicating low public attention.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.0.2, < 1.0.2kCPE matchmatch criteria
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
>= 1.1.0, < 1.1.0cCPE matchmatch criteria
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
>= 4.0.0, <= 4.1.2CPE matchmatch criteria
cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:*
>= 4.2.0, < 4.7.3CPE matchmatch criteria
cpe:2.3:a:nodejs:node.js:*:*:*:*:lts:*:*:*
>= 6.0.0, <= 6.8.1CPE matchmatch criteria
cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.9MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
2.2
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
14.22%
Probability of exploitation in next 30 days
EPSS Percentile
96.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.1422 is in the 96th percentile among its peer group of 19,955 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (31)

oraclepatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-apache-commons-daemon-0:1.1.0-1.redhat_2.1.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-apache-commons-daemon-jsvc-1:1.1.0-1.redhat_2.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-apr-0:1.6.3-14.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-apr-util-0:1.6.1-9.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-httpd-0:2.4.29-17.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-mod_auth_kerb-0:5.4-36.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-mod_bmx-0:0.9.6-17.GA.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-mod_cluster-native-0:1.3.8-1.Final_redhat_2.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-mod_jk-0:1.2.43-1.redhat_1.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-mod_rt-0:2.4.1-19.GA.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-mod_security-0:2.9.1-23.GA.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-nghttp2-0:1.29.0-8.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-openssl-1:1.0.2n-11.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-apache-commons-daemon-0:1.1.0-1.redhat_2.1.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-apache-commons-daemon-jsvc-1:1.1.0-1.redhat_2.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-apr-0:1.6.3-14.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-apr-util-0:1.6.1-9.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-httpd-0:2.4.29-17.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-mod_auth_kerb-0:5.4-36.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-mod_bmx-0:0.9.6-17.GA.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-mod_cluster-native-0:1.3.8-1.Final_redhat_2.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-mod_jk-0:1.2.43-1.redhat_1.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-mod_rt-0:2.4.1-19.GA.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-mod_security-0:2.9.1-23.GA.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-nghttp2-0:1.29.0-8.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-openssl-1:1.0.2n-11.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: Text-Only JBCS
View patch
redhatend of lifevia redhat_api
Product: Red Hat JBoss Core ServicesFixed in: openssl
redhatend of lifevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 6Fixed in: openssl
redhatend of lifevia redhat_api
Product: Red Hat JBoss Enterprise Web Server 2Fixed in: openssl

Vendor Advisories (1)

redhatCVE-2016-7055Low

openssl: Carry propagating bug in Montgomery multiplication

Oct 11, 2016

References

access.redhat.com / errata/RHSA-2018:2185
Third Party Advisory
access.redhat.com / errata/RHSA-2018:2186
Third Party Advisory
access.redhat.com / errata/RHSA-2018:2187
Third Party Advisory
h20566.www2.hpe.com / hpsc/doc/public/display
Third Party Advisory
h20566.www2.hpe.com / hpsc/doc/public/display
Third Party AdvisoryVDB Entry
security.freebsd.org / advisories/FreeBSD-SA-17:02.openssl.asc
Third Party Advisory
security.gentoo.org / glsa/201702-07
Third Party Advisory
openssl.org / news/secadv/20161110.txt
Vendor Advisory
oracle.com / technetwork/security-advisory/cpuapr2019-5072813.html
PatchThird Party Advisory
tenable.com / security/tns-2017-04
Third Party Advisory
oracle.com / technetwork/security-advisory/cpujan2018-3236628.html
PatchThird Party Advisory
oracle.com / technetwork/security-advisory/cpujul2017-3236622.html
PatchThird Party Advisory
oracle.com / technetwork/security-advisory/cpuoct2017-3236626.html
PatchThird Party Advisory
securityfocus.com / bid/94242
Third Party AdvisoryUS Government ResourceVDB Entry
securitytracker.com / id/1037261
Third Party AdvisoryVDB Entry