PatchSiren

Dest Unreach CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Dest Unreach CVE published 2017-01-30

CVE-2016-2217

CVE-2016-2217 is a weak-cryptography issue in Socat’s OpenSSL address implementation. According to the CVE description, affected Socat versions 1.7.3.0 and 2.0.0-b8 do not use a prime number for the Diffie-Hellman parameter, which can make it easier for a remote attacker to obtain the shared secret. The NVD assigns CWE-320 and a medium CVSS 3.0 score of 5.3.