VDB
CVE-2016-0270
CVE-2016-0270
PUBLISHED
CVSS 5.900000095367432 MEDIUM
IBM Domino 9.0.1 Fix Pack 3 Interim Fix 2 through 9.0.1 Fix Pack 5 Interim Fix 1, when using TLS and AES GCM, uses random nonce generation, which makes it easier for remote attackers to obtain the authentication key and spoof data by leveraging the reuse of a nonce in a session and a "forbidden attack." NOTE: this CVE has been incorrectly used for GCM nonce reuse issues in other products; see CVE-2016-10213 for the A10 issue, CVE-2016-10212 for the Radware issue, and CVE-2017-5933 for the Citrix issue.
EPSS 0.54% · 68.0th percentile
Risk Scores
CVSS 3.0
5.900000095367432
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.54%
68.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| ibm | client_application_access | 1.0.0.1 |
| ibm | domino | 9.0.1.4, 9.0.1.5, 9.0.1.3 |
| n/a | n/a | n/a |
| ibm | notes | 9.0.1.3, 9.0.1.5, 9.0.1.4 |
Exploit Intelligence
- 96062 (circl)
- http://www-01.ibm.com/support/docview.wss?uid=swg21979604 (circl)
- https://github.com/nonce-disrespect/nonce-disrespect (circl)
- http://www-01.ibm.com/support/docview.wss?uid=swg21979673 (circl)
- https://support.citrix.com/article/CTX220329 (circl)
- http://www-01.ibm.com/support/docview.wss?uid=swg21979669 (circl)
- 1037795 (circl)
Timeline
- Feb 8, 2017 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 3, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 8, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 16, 2023 EPSS Score
References
- 96062 vdb
- http://www-01.ibm.com/support/docview.wss?uid=swg21979604 url
- https://github.com/nonce-disrespect/nonce-disrespect url
- http://www-01.ibm.com/support/docview.wss?uid=swg21979673 url
- https://support.citrix.com/article/CTX220329 url
- http://www-01.ibm.com/support/docview.wss?uid=swg21979669 url
- 1037795 vdb
- https://support.citrix.com/article/CTX219885 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2016-0270 advisory