Vulnerability record · CVE-2016-2107 · published 5 May 2016
CVE-2016-2107: OpenSSL AES-NI CBC padding oracle leaks cleartext
Redhat · Enterprise Linux Desktop
The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not account for memory allocation during a padding check, creating a padding-oracle condition in AES CBC sessions. This is an incorrect fix for CVE-2013-0169, so the earlier Lucky-13 class issue was not fully closed. It matters because a remote attacker can recover sensitive cleartext from encrypted sessions.
Description
The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obtain sensitive cleartext information via a padding-oracle attack against an AES CBC session. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-0169.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityCVSS is only Medium (5.9) and there is no KEV listing, but the very high EPSS score and broad multi-vendor exposure make timely patching important.
What it is
The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not account for memory allocation during a padding check, creating a padding-oracle condition in AES CBC sessions. This is an incorrect fix for CVE-2013-0169, so the earlier Lucky-13 class issue was not fully closed. It matters because a remote attacker can recover sensitive cleartext from encrypted sessions.
Impact
An attacker can distinguish padding validity and use that oracle to decrypt captured AES CBC traffic, exposing sensitive cleartext such as credentials or session data. There is no integrity or availability impact; the loss is confidentiality.
Attack surface
Reachable remotely over the network against TLS/SSL services using AES CBC with the AES-NI code path; no authentication or user interaction is required per the CVSS vector (AV:N/PR:N/UI:N). The attack requires the ability to observe and manipulate encrypted traffic, which is why AC is rated High.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high (0.89058, 99.771st percentile), indicating strong predicted exploitation activity. References are advisories and patches only, with no public exploit tag.
What to do
- Upgrade OpenSSL to 1.0.1t or 1.0.2h or later, or apply the vendor backport for your distribution (Red Hat, Debian, Ubuntu, SUSE, Android, Node.js).
- Where immediate patching is not possible, disable AES-NI or prefer AES-GCM/ChaCha20-Poly1305 cipher suites to avoid the CBC padding check path.
- Inventory all embedded OpenSSL copies (appliances, Java/Node runtimes, Android builds) and patch them, since the affected products list spans many vendors.
- Reissue or rotate credentials and session keys that may have transited vulnerable AES CBC sessions.
Detection
- Search TLS logs and packet captures for repeated AES CBC handshakes or record failures from a single source, consistent with padding-oracle probing.
- Fingerprint TLS stacks to identify servers still negotiating AES CBC with AES-NI-accelerated OpenSSL builds.
- Scan internal and external hosts for OpenSSL versions below 1.0.1t / 1.0.2h and flag unpatched embedded libraries.
- Monitor for anomalous decryption success patterns or repeated connection retries against CBC-protected endpoints.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
15 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2016-2107 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-2107), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.