Skip to main content

Cryptographic Issues


Severity Low
Score 3.4/10


The SSL protocol 3.0, as used in OpenSSL through 0.9.8zb, 1.0.0 through 1.0.0n, 1.0.1 through 1.0.1i and 1.0.2-beta1 through 1.0.2-beta3, and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.

  • HIGH
  • NONE
  • NONE
  • LOW
  • NONE

CWE-310 - Cryptographic Issues

Cryptographic issues is a category of weaknesses related to the design and implementation of the confidentiality and integrity of data. If not addressed, the weaknesses in this category can lead to data quality degradation.

Advisory Timeline

  • Published