Is Symantec Web Gateway vulnerable to Padding-Oracle in AES-NI CBC MAC check (CVE-2016-2107)?
search cancel

Is Symantec Web Gateway vulnerable to Padding-Oracle in AES-NI CBC MAC check (CVE-2016-2107)?

book

Article ID: 164673

calendar_today

Updated On:

Products

Web Gateway

Issue/Introduction

This article contains information about Symantec Web Gateway and vulnerability to Padding-Oracle in AES-NI CBC MAC check (CVE-2016-2107)

Resolution

Please note that Symantec Web Gateway (SWG) is not vulnerable to this attack.

SWG's OpenSSL is not built to leverage the Intel "special" instructions, hence can't support "AES-NI", which is a requirement for this vulnerability.