← Vulnerability feed

Vulnerability record · CVE-2016-0800 · published 1 March 2016

CVE-2016-0800: OpenSSL SSLv2 Bleichenbacher padding oracle enables DROWN decryption

OOpenssl · Openssl

OpenSSL before 1.0.1s and 1.0.2 before 1.0.2g, along with other products, support SSLv2 in a way that exposes a Bleichenbacher RSA padding oracle. A server sends a ServerVerify message before confirming the client holds certain plaintext RSA data, which lets remote attackers decrypt TLS ciphertext. This matters because any server still accepting SSLv2 can have its TLS sessions decrypted, exposing credentials and other sensitive traffic.

5.9 CVSS 3.0 Medium EPSS 82% · top 0.4% CWE-200 · Information exposureCWE-310 · CWE-310
5.9CVSS 3.0 base score, v2 4.3
82%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
126References
17 Jun 2026Last modified by NVD

Description

The SSLv2 protocol, as used in OpenSSL before 1.0.1s and 1.0.2 before 1.0.2g and other products, requires a server to send a ServerVerify message before establishing that a client possesses certain plaintext RSA data, which makes it easier for remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a "DROWN" attack.

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityThe flaw allows decryption of TLS traffic with no authentication or user interaction, and EPSS is very high even though KEV does not list it.

What it is

OpenSSL before 1.0.1s and 1.0.2 before 1.0.2g, along with other products, support SSLv2 in a way that exposes a Bleichenbacher RSA padding oracle. A server sends a ServerVerify message before confirming the client holds certain plaintext RSA data, which lets remote attackers decrypt TLS ciphertext. This matters because any server still accepting SSLv2 can have its TLS sessions decrypted, exposing credentials and other sensitive traffic.

Impact

An attacker who can capture TLS traffic can decrypt it, recovering plaintext such as session cookies, credentials and other confidential data. The flaw is an information disclosure only; there is no integrity or availability impact.

Attack surface

Reachable over the network with no authentication and no user interaction, per the CVSS vector AV:N/AC:H/PR:N/UI:N. The attacker needs to be able to send SSLv2 handshake traffic to a server that still supports SSLv2, and typically also needs to observe or capture the target TLS session.

Exploitation

CISA KEV does not list this CVE, but EPSS is very high at 0.82112 (99.6th percentile), indicating strong likelihood of attempted exploitation. No reference is tagged as an exploit, so public exploit availability is not confirmed by this record.

What to do

  • Upgrade OpenSSL to 1.0.1s, 1.0.2g or later, or apply the vendor patch for your distribution.
  • Disable SSLv2 entirely on all servers and services; do not rely on client-side restrictions alone.
  • Rotate private keys and reissue certificates for any server that may have accepted SSLv2 traffic, since captured sessions may already be decryptable.
  • Inventory all TLS endpoints, including appliances and third-party products such as Pulse Secure and Steel Belted Radius, and confirm SSLv2 is off.
  • Block or alert on inbound SSLv2 handshakes at the network perimeter where feasible.

Detection

  • Scan TLS endpoints for SSLv2 support and alert on any server that negotiates or advertises SSLv2.
  • Monitor network traffic for SSLv2 ClientHello and ServerVerify patterns on TLS ports.
  • Review TLS server configuration baselines for enabled SSLv2 ciphers and flag drift.
  • Correlate large volumes of failed or repeated RSA handshake attempts against TLS services as possible padding-oracle probing.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10722
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10759
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00001.html
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00002.html
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00003.html
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00004.html
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00005.html
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00006.html
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00007.html
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00009.html
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00010.html
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.html
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00012.html
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00017.html
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00025.html
http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00038.html
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00015.html
http://lists.opensuse.org/opensuse-security-announce/2016-05/msg00017.html
http://marc.info/?l=bugtraq&m=145983526810210&w=2
http://marc.info/?l=bugtraq&m=146108058503441&w=2
http://marc.info/?l=bugtraq&m=146133665209436&w=2
http://rhn.redhat.com/errata/RHSA-2016-1519.html
http://support.citrix.com/article/CTX208403
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160302-openssl
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20160330-01-openssl-en
http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html
http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html
http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html
http://www.securityfocus.com/bid/83733
http://www.securityfocus.com/bid/91787
http://www.securitytracker.com/id/1035133
http://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-623229.pdf
https://access.redhat.com/security/vulnerabilities/drown
https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdf
https://cert-portal.siemens.com/productcert/pdf/ssa-623229.pdf
https://drownattack.com

Track CVE-2016-0800 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2014-0160OpenSSL TLS/DTLS Heartbeat Extension Out-of-Bounds Read (Heartbleed)OpenSSL 1.0.1 before 1.0.1g mishandles Heartbeat Extension packets in its TLS and DTLS implementations, causing an out-of-bounds read of process memo…KEVEPSS 100%analysed10.0CVE-2009-3245Openssl improper input validation vulnerabilityOpenSSL before 0.9.8m does not check for a NULL return value from bn_wexpand function calls in (1) crypto/bn/bn_div.c, (2) crypto/bn/bn_gf2m.c, (3) c…EPSS 6.5%10.0CVE-2006-3738OpenSSL SSL_get_shared_ciphers buffer overflow via long cipher listOpenSSL versions before 0.9.7l and 0.9.8d contain a buffer overflow in the SSL_get_shared_ciphers function, triggered by a long list of ciphers. The …EPSS 49%analysed9.8CVE-2026-63073Openssl vulnerabilityIssue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished name directly as the format string to `ERR_raise_da…EPSS 1.2%9.8CVE-2026-31789Openssl out-of-bounds write vulnerabilityIssue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms. Impact…EPSS 0.33%9.8CVE-2022-2274OpenSSL 3.0.4 RSA AVX512IFMA memory corruptionOpenSSL 3.0.4 introduced a bug in the RSA implementation for X86_64 CPUs supporting AVX512IFMA instructions, causing 2048-bit private key operations …EPSS 46%analysed9.8CVE-2021-3711OpenSSL SM2 decryption buffer overflowOpenSSL's SM2 decryption code miscalculates the output buffer size needed by EVP_PKEY_decrypt(), so the first sizing call can return a value smaller …EPSS 88%analysed9.8CVE-2016-6309OpenSSL 1.1.0a statem use-after-free on realloc in TLS session handlingOpenSSL 1.1.0a's statem/statem.c fails to account for memory-block movement after a realloc call, leaving a dangling pointer that can be used after f…EPSS 70%analysed

Source: NIST National Vulnerability Database (record CVE-2016-0800), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.