header

Denial of Service (DoS) Vulnerability in OpenSSL DTLS Anti-replay (CVE-2016-2181)


Mar 10, 2023
Share

Denial of Service (DoS) vulnerability in the anti-replay functionality of OpenSSL's DTLS implementation (CVE-2016-2181)

Summary

This vulnerability applies when DTLS functionality is enabled. No Buffalo NAS products have enabled the DTLS function of OpenSSL, and so no Buffalo Sytems are affected by this vulnerability.

Vulnerability ID Vulnerability Overview
CVE-2016-2181 The Anti-Replay feature in the DTLS implementation in OpenSSL before 1.1.0 mishandles early use of a new epoch number in conjunction with a large sequence number, which allows remote attackers to cause a denial of service (false-positive packet drops) via spoofed DTLS records, related to rec_layer_d1.c and ssl3_record.c.

Affected Supported TeraStations

None

Back to Security Notices

Date Description
3/10/2022 Initial release
X