SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2012-2333

Integer underflow in OpenSSL before 0.9.8x, 1.0.0 before 1.0.0j, and 1.0.1 before 1.0.1c, when TLS 1.1, TLS 1.2, or DTLS is used with CBC encryption, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified…

MEDIUM 6.8EPSS 28.2%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 28.2%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.

Description

Integer underflow in OpenSSL before 0.9.8x, 1.0.0 before 1.0.0j, and 1.0.1 before 1.0.1c, when TLS 1.1, TLS 1.2, or DTLS is used with CBC encryption, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted TLS packet that is not properly handled during a certain explicit IV calculation.

CVSS 2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
28.15% probability · 98th percentile
CISA KEV
Not listed
Weakness
CWE-189
Affected
openssl/openssl · redhat/openssl
Source
secalert@redhat.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.