{"api_version":"1","generated_at":"2026-07-23T18:56:32+00:00","cve":"CVE-2016-0270","urls":{"html":"https://cve.report/CVE-2016-0270","api":"https://cve.report/api/cve/CVE-2016-0270.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2016-0270","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2016-0270"},"summary":{"title":"CVE-2016-0270","description":"IBM Domino 9.0.1 Fix Pack 3 Interim Fix 2 through 9.0.1 Fix Pack 5 Interim Fix 1, when using TLS and AES GCM, uses random nonce generation, which makes it easier for remote attackers to obtain the authentication key and spoof data by leveraging the reuse of a nonce in a session and a \"forbidden attack.\" NOTE: this CVE has been incorrectly used for GCM nonce reuse issues in other products; see CVE-2016-10213 for the A10 issue, CVE-2016-10212 for the Radware issue, and CVE-2017-5933 for the Citrix issue.","state":"PUBLISHED","assigner":"ibm","published_at":"2017-02-08 16:59:00","updated_at":"2025-04-20 01:37:25"},"problem_types":["CWE-200","n/a"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"5.9","severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securitytracker.com/id/1037795","name":"http://www.securitytracker.com/id/1037795","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Citrix NetScaler Nonce Generation Flaw Lets Remote Users Obtain Potentially Sensitive Information on the Target System - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21979604","name":"http://www-01.ibm.com/support/docview.wss?uid=swg21979604","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mitigation","Patch","Vendor Advisory"],"title":"IBM Security Bulletin: Vulnerability in IBM Domino Web Server TLS AES GCM Nonce Generation - United States","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21979673","name":"http://www-01.ibm.com/support/docview.wss?uid=swg21979673","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mitigation","Patch","Vendor Advisory"],"title":"IBM Security Bulletin: Vulnerability in IBM Client Application Access TLS AES GCM Nonce Generation (CVE-2016-0270) - United States","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/96062","name":"http://www.securityfocus.com/bid/96062","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"IBM Domino CVE-2016-0270 Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://github.com/nonce-disrespect/nonce-disrespect","name":"https://github.com/nonce-disrespect/nonce-disrespect","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"GitHub - nonce-disrespect/nonce-disrespect: Nonce-Disrespecting Adversaries: Practical Forgery Attacks on GCM in TLS","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21979669","name":"http://www-01.ibm.com/support/docview.wss?uid=swg21979669","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mitigation","Patch","Vendor Advisory"],"title":"IBM Security Bulletin: Vulnerability in IBM Notes TLS AES GCM Nonce Generation (CVE-2016-0270) - United States","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"https://support.citrix.com/article/CTX220329","name":"https://support.citrix.com/article/CTX220329","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Vulnerability in Citrix NetScaler Application Delivery Controller and NetScaler Gateway GCM nonce generation","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2016-0270","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2016-0270","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2016","cve_id":"270","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"client_application_access","cpe6":"1.0.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"270","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"domino","cpe6":"9.0.1.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"270","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"domino","cpe6":"9.0.1.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"270","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"domino","cpe6":"9.0.1.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"270","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"notes","cpe6":"9.0.1.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"270","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"notes","cpe6":"9.0.1.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"270","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"notes","cpe6":"9.0.1.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-05T22:15:23.329Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"96062","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/96062"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21979604"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://github.com/nonce-disrespect/nonce-disrespect"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21979673"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://support.citrix.com/article/CTX220329"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21979669"},{"name":"1037795","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1037795"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2016-03-28T00:00:00.000Z","descriptions":[{"lang":"en","value":"IBM Domino 9.0.1 Fix Pack 3 Interim Fix 2 through 9.0.1 Fix Pack 5 Interim Fix 1, when using TLS and AES GCM, uses random nonce generation, which makes it easier for remote attackers to obtain the authentication key and spoof data by leveraging the reuse of a nonce in a session and a \"forbidden attack.\" NOTE: this CVE has been incorrectly used for GCM nonce reuse issues in other products; see CVE-2016-10213 for the A10 issue, CVE-2016-10212 for the Radware issue, and CVE-2017-5933 for the Citrix issue."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-11-14T10:57:01.000Z","orgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","shortName":"ibm"},"references":[{"name":"96062","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/96062"},{"tags":["x_refsource_CONFIRM"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21979604"},{"tags":["x_refsource_MISC"],"url":"https://github.com/nonce-disrespect/nonce-disrespect"},{"tags":["x_refsource_CONFIRM"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21979673"},{"tags":["x_refsource_CONFIRM"],"url":"https://support.citrix.com/article/CTX220329"},{"tags":["x_refsource_CONFIRM"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21979669"},{"name":"1037795","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1037795"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"psirt@us.ibm.com","ID":"CVE-2016-0270","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"IBM Domino 9.0.1 Fix Pack 3 Interim Fix 2 through 9.0.1 Fix Pack 5 Interim Fix 1, when using TLS and AES GCM, uses random nonce generation, which makes it easier for remote attackers to obtain the authentication key and spoof data by leveraging the reuse of a nonce in a session and a \"forbidden attack.\" NOTE: this CVE has been incorrectly used for GCM nonce reuse issues in other products; see CVE-2016-10213 for the A10 issue, CVE-2016-10212 for the Radware issue, and CVE-2017-5933 for the Citrix issue."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"96062","refsource":"BID","url":"http://www.securityfocus.com/bid/96062"},{"name":"http://www-01.ibm.com/support/docview.wss?uid=swg21979604","refsource":"CONFIRM","url":"http://www-01.ibm.com/support/docview.wss?uid=swg21979604"},{"name":"https://github.com/nonce-disrespect/nonce-disrespect","refsource":"MISC","url":"https://github.com/nonce-disrespect/nonce-disrespect"},{"name":"http://www-01.ibm.com/support/docview.wss?uid=swg21979673","refsource":"CONFIRM","url":"http://www-01.ibm.com/support/docview.wss?uid=swg21979673"},{"name":"https://support.citrix.com/article/CTX220329","refsource":"CONFIRM","url":"https://support.citrix.com/article/CTX220329"},{"name":"http://www-01.ibm.com/support/docview.wss?uid=swg21979669","refsource":"CONFIRM","url":"http://www-01.ibm.com/support/docview.wss?uid=swg21979669"},{"name":"1037795","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1037795"}]}}}},"cveMetadata":{"assignerOrgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","assignerShortName":"ibm","cveId":"CVE-2016-0270","datePublished":"2017-02-08T16:00:00.000Z","dateReserved":"2015-12-08T00:00:00.000Z","dateUpdated":"2024-08-05T22:15:23.329Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-02-08 16:59:00","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["CWE-200","n/a"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:client_application_access:1.0.0.1:*:*:*:*:*:*:*","matchCriteriaId":"D8173749-67C8-46D1-8505-200ADF7A70D2"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:domino:9.0.1.3:*:*:*:*:*:*:*","matchCriteriaId":"BF7A97DE-36BC-4DFC-9F44-EF2C155703B7"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:domino:9.0.1.4:*:*:*:*:*:*:*","matchCriteriaId":"4C05B1F1-EDFC-46AC-B701-13652ABA7065"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:domino:9.0.1.5:*:*:*:*:*:*:*","matchCriteriaId":"D246A5C6-E12D-4B5D-8319-0A9F52899173"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:notes:9.0.1.3:*:*:*:*:*:*:*","matchCriteriaId":"A6C10DAB-5579-4273-9B5E-58199A978DD6"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:notes:9.0.1.4:*:*:*:*:*:*:*","matchCriteriaId":"AFAB1EE7-3835-4AD6-8F13-01C1CB62F98D"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:notes:9.0.1.5:*:*:*:*:*:*:*","matchCriteriaId":"320A0EC3-D4DC-4CEC-B71A-47658A8C17AC"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2016","CveId":"270","Ordinal":"1","Title":"CVE-2016-0270","CVE":"CVE-2016-0270","Year":"2016"},"notes":[{"CveYear":"2016","CveId":"270","Ordinal":"1","NoteData":"IBM Domino 9.0.1 Fix Pack 3 Interim Fix 2 through 9.0.1 Fix Pack 5 Interim Fix 1, when using TLS and AES GCM, uses random nonce generation, which makes it easier for remote attackers to obtain the authentication key and spoof data by leveraging the reuse of a nonce in a session and a \"forbidden attack.\" NOTE: this CVE has been incorrectly used for GCM nonce reuse issues in other products; see CVE-2016-10213 for the A10 issue, CVE-2016-10212 for the Radware issue, and CVE-2017-5933 for the Citrix issue.","Type":"Description","Title":"CVE-2016-0270"},{"CveYear":"2016","CveId":"270","Ordinal":"2","NoteData":"2017-02-08","Type":"Other","Title":"Published"},{"CveYear":"2016","CveId":"270","Ordinal":"3","NoteData":"2017-11-14","Type":"Other","Title":"Modified"}]}}}