CVE-2016-6307

Description

The state-machine implementation in OpenSSL 1.1.0 before 1.1.0a allocates memory before checking for an excessive length, which might allow remote attackers to cause a denial of service (memory consumption) via crafted TLS messages, related to statem/statem.c and statem/statem_lib.c.

Risk Information

Base Score
5.9
MODERATE
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
20.873

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2016-6305,CVE-2016-6304,CVE-2016-6308,CVE-2016-6307 are fixed in OpenSSL (x64) 1.1.0aWindows
Multiple vulnerabilities are fixed in Nessus 6.9Windows
Multiple vulnerabilities are fixed in Tenable Nessus 6.9Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 10.2.0Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 10.2.1Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 10.1.1Windows
Multiple Vulnerabilities are affected in IBM Cognos Controller 10.1.0Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.0.5.0Windows
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Adaptive Security Appliance (ASA) SoftwareNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco AnyConnect Secure Mobility ClientNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Application and Content Networking System (ACNS) SoftwareNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Digital Content Manager (DCM) SoftwareNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Emergency ResponderNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco IP Phone 7800 SeriesNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Jabber for MacNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Jabber for WindowsNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Jabber GuestNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Jabber Software Development KitNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco MediaSenseNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Paging ServerNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Plug-in for OpenFlowNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Prime InfrastructureNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Prime Network Services ControllerNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco TelePresence ISDN LinkNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco TelePresence Serial Gateway SeriesNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco UCS DirectorNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Unified Contact Center EnterpriseNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Unified Intelligence CenterNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Unified MeetingPlaceNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Unified SIP ProxyNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Unity ConnectionNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Unity ExpressNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Video Surveillance 6000 Series IP CamerasNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco ASR 5000 SeriesNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco IronPort Encryption Appliance SoftwareNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Firepower Management Center Virtual ApplianceNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco IronPort Security Management Appliance SoftwareNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Data Center Network ManagerNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Intercloud FabricNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Nexus 1000V Switch for VMware vSphereNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For CiscoPro Workgroup EtherSwitch SoftwareNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Unified Computing SystemNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco UCS Central SoftwareNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco ASR 1000 Series Aggregation Services RoutersNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Cloud Services Router 1000V SeriesNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco 4000 Series Integrated Services RoutersNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco 1000 Series Integrated Services RoutersNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For CiscoWorks Common Services SoftwareNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Wireless Network Management Software SuiteNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Prime CollaborationNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Virtual Wireless ControllerNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Network Convergence System 540 Series RoutersNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Digital Media ManagerNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Video Networking SolutionsNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco TelePresence ISDN GatewayNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco TelePresence MCU 4500 SeriesNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco TelePresence MSE 8000 SeriesNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco MXE 3000 Series (Media Experience Engines)NCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Unified Communications LicensingNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco TelePresence Content ServerNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco TelePresence ServerNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco TelePresence Video Communication Server SoftwareNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco IPICS Server SoftwareNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco ConductorNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Enterprise CDN SoftwareNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco NAC Appliance (Clean Access)NCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco NAC Appliance 3300 SeriesNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Wide Area Application Services (WAAS) AppliancesNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Support ToolsNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco ONS 15454 Series Multiservice Provisioning PlatformsNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Video Surveillance 4000 Series IP CamerasNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Video Surveillance ManagerNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Identity Services EngineNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Small Business Voice Gateways and ATAsNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco IPS 4200 Series SensorsNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco 1000 Series Connected Grid RoutersNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Unified Attendant ConsolesNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Unified Communications Manager (CallManager)NCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Hosted Collaboration Solution (HCS)NCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Jabber for iPhoneNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco SIP IP Phone SoftwareNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco IP Phone 8800 SeriesNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco IP Phone FW 7900 Series SoftwareNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Unified Mobile CommunicatorNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Telepresence Integrator C SeriesNCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For NCM
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: September 2016 For Cisco Policy Suite for MobileNCM
Uncontrolled Resource Consumption Vulnerability (CVE-2016-6307)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-1706057Security Update for Cisco Adaptive Security Appliance (ASA) Software 99.17(1.69)
PATCH-1705981Security Update for Cisco AnyConnect Secure Mobility Client 4.3(2034)
PATCH-1705634Security Update for Cisco Application and Content Networking System (ACNS) Software 3.0(0)A5(3.1a)
PATCH-1706007Security Update for Cisco Digital Content Manager (DCM) Software 20.0.0
PATCH-1706049Security Update for Cisco Emergency Responder 12.0(0.98000.50)
PATCH-1705975Security Update for Cisco IP Phone 7800 Series 11.7(1)
PATCH-1705811Security Update for Cisco Jabber for Windows 11.6(1.38147)
PATCH-1705783Security Update for Cisco Jabber Guest 10.6(11)
PATCH-1706051Security Update for Cisco Jabber Software Development Kit 11.8(2)
PATCH-1705879Security Update for Cisco MediaSense 11.5(1.10000.6)
PATCH-1706011Security Update for Cisco Paging Server 12.0(1)
PATCH-1701673Security Update for Cisco Plug-in for OpenFlow 4.12(0)SP1
PATCH-1705595Security Update for Cisco Prime Infrastructure 2.2(2)
PATCH-1701930Security Update for Cisco Prime Network Services Controller 21.2.A0.65491
PATCH-1705893Security Update for Cisco TelePresence ISDN Link IL1.1.7
PATCH-1705959Security Update for Cisco TelePresence Serial Gateway Series 1.0(1.52)
PATCH-1705947Security Update for Cisco UCS Director 6.0(1.0)
PATCH-1705943Security Update for Cisco Unified Contact Center Enterprise 11.6(1)SR0(0)
PATCH-1705886Security Update for Cisco Unified Intelligence Center 11.5(0.98000.126)
PATCH-1705973Security Update for Cisco Unified MeetingPlace 8.6(2.45)
PATCH-1705497Security Update for Cisco Unified SIP Proxy 8.5(5)
PATCH-1706048Security Update for Cisco Unity Connection 12.0(0.97000.184)
PATCH-1703070Security Update for Cisco Unity Express 6.2.1
PATCH-1705965Security Update for Cisco Video Surveillance 6000 Series IP Cameras 2.9
PATCH-1706032Security Update for Cisco ASR 5000 Series 21.3.A0.66703
PATCH-1705938Security Update for Cisco Firepower Management Center Virtual Appliance 6.1.0.1
PATCH-1706033Security Update for Cisco IronPort Security Management Appliance Software 11.0.1-152
PATCH-1706034Security Update for Cisco Data Center Network Manager 10.1(1.158)S0
PATCH-1705855Security Update for Cisco Intercloud Fabric 3.3(1)
PATCH-1705949Security Update for Cisco Nexus 1000V Switch for VMware vSphere 5.2(1)SV3(3.1)
PATCH-1706035Security Update for CiscoPro Workgroup EtherSwitch Software 6.0(2)A8(4)
PATCH-1706036Security Update for Cisco Unified Computing System 3.2(1d)
PATCH-1705950Security Update for Cisco UCS Central Software 2.0(1a)
PATCH-1705898Security Update for Cisco ASR 1000 Series Aggregation Services Routers Denali-16.3.4a
PATCH-1705899Security Update for Cisco Cloud Services Router 1000V Series Denali-16.3.4a
PATCH-1705901Security Update for Cisco 4000 Series Integrated Services Routers Denali-16.3.4a
PATCH-1705902Security Update for Cisco 1000 Series Integrated Services Routers Denali-16.3.4a
PATCH-1705477Security Update for CiscoWorks Common Services Software 4.2(4)
PATCH-1705952Security Update for Cisco Wireless Network Management Software Suite 8.0(150)
PATCH-1705997Security Update for Cisco Prime Collaboration 11.0(0.815)
PATCH-1705937Security Update for Cisco Virtual Wireless Controller 8.3(15.155)
PATCH-1706041Security Update for Cisco Network Convergence System 540 Series Routers 6.4.1.8i.BASE
PATCH-1705797Security Update for Cisco Digital Media Manager 5.6.3
PATCH-1705954Security Update for Cisco Video Networking Solutions 2.6.9
PATCH-1705955Security Update for Cisco TelePresence ISDN Gateway 2.2(1.122)
PATCH-1705864Security Update for Cisco TelePresence MCU 4500 Series 4.5(1.89)
PATCH-1705956Security Update for Cisco TelePresence MSE 8000 Series 2.3(1.51)
PATCH-1705957Security Update for Cisco MXE 3000 Series (Media Experience Engines) 3.5.2
PATCH-1706042Security Update for Cisco Unified Communications Licensing 11.5(1.12001.2)
PATCH-1705866Security Update for Cisco TelePresence Content Server 7.2
PATCH-1705960Security Update for Cisco TelePresence Server 4.4(1.16)
PATCH-1706044Security Update for Cisco TelePresence Video Communication Server Software X8.9.2
PATCH-1705988Security Update for Cisco IPICS Server Software 4.10(2)
PATCH-1705867Security Update for Cisco Conductor 3.600
PATCH-1705827Security Update for Cisco Enterprise CDN Software 5.5(41.2)
PATCH-1705725Security Update for Cisco NAC Appliance (Clean Access) 4.9(5)
PATCH-1706001Security Update for Cisco Wide Area Application Services (WAAS) Appliances 6.3(0.185)
PATCH-1705963Security Update for Cisco ONS 15454 Series Multiservice Provisioning Platforms 10.6(2)
PATCH-1705964Security Update for Cisco Video Surveillance 4000 Series IP Cameras 2.4(6.310)
PATCH-1706045Security Update for Cisco Video Surveillance Manager 7.10
PATCH-1706002Security Update for Cisco Identity Services Engine 2.0(0.905)
PATCH-1702213Security Update for Cisco Small Business Voice Gateways and ATAs 7.6.2SR5
PATCH-1705754Security Update for Cisco IPS 4200 Series Sensors 7.3(5)P1
PATCH-1705873Security Update for Cisco 1000 Series Connected Grid Routers 15.6(3.0q)M
PATCH-1706047Security Update for Cisco Unified Attendant Consoles 11.0(2)
PATCH-1706016Security Update for Cisco Unified Communications Manager (CallManager) CUP.11.5(1.12900.25)
PATCH-1706050Security Update for Cisco Hosted Collaboration Solution (HCS) 11.5(1.93540.24)
PATCH-1705972Security Update for Cisco Jabber for iPhone 11.8(1.250291)
PATCH-1705918Security Update for Cisco SIP IP Phone Software 11.7(1)MN19
PATCH-1705974Security Update for Cisco IP Phone 8800 Series 11.7(1)SC2
PATCH-1705386Security Update for Cisco IP Phone FW 7900 Series Software 9.4(2)TH1.1
PATCH-1705976Security Update for Cisco Unified Mobile Communicator 11.8(1.250274)
PATCH-1706043Security Update for Cisco Telepresence Integrator C Series 9.1.1
PATCH-1706026Security Update for CAF-1.2.0.0
PATCH-1705812Security Update for Cisco Policy Suite for Mobile 8.1.0

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234