peter bassill · operator
$ cve CVE-2014-0160 JSON

CVE-2014-0160 KEV EXPLOIT

7.5
HIGH · CVSS 3.1 · EPSS 100% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-05-25.

Description

The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.

Scoring

CVSS7.5 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS100% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-125
On CISA KEVyes — remediate by 2022-05-25
Public exploityes
Published2014-04-07
Last modified2026-06-17

CISA KEV

NameOpenSSL Information Disclosure Vulnerability
Added2022-05-04
Due2022-05-25
Vendor / productOpenSSL / OpenSSL
Ransomware usenone reported

Affected (35)

VendorProduct
broadcomsymantec messaging gateway
canonicalubuntu linux
debiandebian linux
fedoraprojectfedora
filezilla-projectfilezilla server
intellianv100
intellianv100 firmware
intellianv60
intellianv60 firmware
mitelmicollab
mitelmivoice
opensslopenssl
opensuseopensuse
redhatenterprise linux desktop
redhatenterprise linux server
redhatenterprise linux server aus
redhatenterprise linux server eus
redhatenterprise linux server tus
redhatenterprise linux workstation
redhatgluster storage
redhatstorage
redhatvirtualization
ricons9922l
ricons9922l firmware
siemensapplication processing engine
siemensapplication processing engine firmware
siemenscp 1543-1
siemenscp 1543-1 firmware
siemenselan-8.2
siemenssimatic s7-1500
siemenssimatic s7-1500 firmware
siemenssimatic s7-1500t
siemenssimatic s7-1500t firmware
siemenswincc open architecture
splunksplunk

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD