676
VMScore

CVE-2016-2462

Published: 09/05/2016 Updated: 10/05/2016
CVSS v2 Base Score: 7.6 | Impact Score: 10 | Exploitability Score: 4.9
CVSS v3 Base Score: 7 | Impact Score: 5.9 | Exploitability Score: 1
VMScore: 676
Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C

Vulnerability Summary

OpenSSLCipher.java in Conscrypt in Android 6.x prior to 2016-05-01 mishandles updates of the Additional Authenticated Data (AAD) array, which allows malicious users to spoof message authentication via unspecified vectors, aka internal bug 27371173.

Vulnerable Product Search on Vulmon Subscribe to Product

google android 6.0.1

google android 6.0