7.6
CVSSv2

CVE-2016-2461

Published: 09/05/2016 Updated: 10/05/2016
CVSS v2 Base Score: 7.6 | Impact Score: 10 | Exploitability Score: 4.9
CVSS v3 Base Score: 7 | Impact Score: 5.9 | Exploitability Score: 1
VMScore: 676
Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C

Vulnerability Summary

OpenSSLCipher.java in Conscrypt in Android 6.x prior to 2016-05-01 mishandles resets of the Additional Authenticated Data (AAD) array, which allows malicious users to spoof message authentication via unspecified vectors, aka internal bugs 27324690 and 27696681.

Vulnerable Product Search on Vulmon Subscribe to Product

google android 6.0.1

google android 6.0