CVE-2016-2850
high-risk
Published 2016-05-13
Botan 1.11.x before 1.11.29 does not enforce TLS policy for (1) signature algorithms and (2) ECC curves, which allows remote attackers to conduct downgrade attacks via unspecified vectors.
Do I need to act?
-
0.43% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.5/10
High
NETWORK
/ LOW complexity
Affected Products (20)
Affected Vendors
References (8)
Vendor Advisory
http://botan.randombit.net/security.html
Vendor Advisory
http://marc.info/?l=botan-devel&m=145852488622892&w=2
Vendor Advisory
http://botan.randombit.net/security.html
Vendor Advisory
http://marc.info/?l=botan-devel&m=145852488622892&w=2
50
/ 100
high-risk
Severity
26/34 · High
Exploitability
2/34 · Minimal
Exposure
22/34 · High