AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2016-4379

LOW · CVSS 3.7 EPSS 1.65%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2016-09-08 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2016-4379
Severity
LOW
CVSS
3.7
EPSS
1.65%
Oracle

Original NVD Description

The TLS implementation in HPE Integrated Lights-Out 3 (aka iLO3) firmware before 1.88 does not properly use a MAC protection mechanism in conjunction with CBC padding, which allows remote attackers to obtain sensitive information via a padding-oracle attack, aka a Vaudenay attack.