Vulnerability record · CVE-2016-0800 · published 1 March 2016
CVE-2016-0800: OpenSSL SSLv2 Bleichenbacher padding oracle enables DROWN decryption
OOpenssl · Openssl
OpenSSL before 1.0.1s and 1.0.2 before 1.0.2g, along with other products, support SSLv2 in a way that exposes a Bleichenbacher RSA padding oracle. A server sends a ServerVerify message before confirming the client holds certain plaintext RSA data, which lets remote attackers decrypt TLS ciphertext. This matters because any server still accepting SSLv2 can have its TLS sessions decrypted, exposing credentials and other sensitive traffic.
Description
The SSLv2 protocol, as used in OpenSSL before 1.0.1s and 1.0.2 before 1.0.2g and other products, requires a server to send a ServerVerify message before establishing that a client possesses certain plaintext RSA data, which makes it easier for remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a "DROWN" attack.
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityThe flaw allows decryption of TLS traffic with no authentication or user interaction, and EPSS is very high even though KEV does not list it.
What it is
OpenSSL before 1.0.1s and 1.0.2 before 1.0.2g, along with other products, support SSLv2 in a way that exposes a Bleichenbacher RSA padding oracle. A server sends a ServerVerify message before confirming the client holds certain plaintext RSA data, which lets remote attackers decrypt TLS ciphertext. This matters because any server still accepting SSLv2 can have its TLS sessions decrypted, exposing credentials and other sensitive traffic.
Impact
An attacker who can capture TLS traffic can decrypt it, recovering plaintext such as session cookies, credentials and other confidential data. The flaw is an information disclosure only; there is no integrity or availability impact.
Attack surface
Reachable over the network with no authentication and no user interaction, per the CVSS vector AV:N/AC:H/PR:N/UI:N. The attacker needs to be able to send SSLv2 handshake traffic to a server that still supports SSLv2, and typically also needs to observe or capture the target TLS session.
Exploitation
CISA KEV does not list this CVE, but EPSS is very high at 0.82112 (99.6th percentile), indicating strong likelihood of attempted exploitation. No reference is tagged as an exploit, so public exploit availability is not confirmed by this record.
What to do
- Upgrade OpenSSL to 1.0.1s, 1.0.2g or later, or apply the vendor patch for your distribution.
- Disable SSLv2 entirely on all servers and services; do not rely on client-side restrictions alone.
- Rotate private keys and reissue certificates for any server that may have accepted SSLv2 traffic, since captured sessions may already be decryptable.
- Inventory all TLS endpoints, including appliances and third-party products such as Pulse Secure and Steel Belted Radius, and confirm SSLv2 is off.
- Block or alert on inbound SSLv2 handshakes at the network perimeter where feasible.
Detection
- Scan TLS endpoints for SSLv2 support and alert on any server that negotiates or advertises SSLv2.
- Monitor network traffic for SSLv2 ClientHello and ServerVerify patterns on TLS ports.
- Review TLS server configuration baselines for enabled SSLv2 ciphers and flag drift.
- Correlate large volumes of failed or repeated RSA handshake attempts against TLS services as possible padding-oracle probing.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2016-0800 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-0800), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.