CVE-2014-0160 KEV EXPLOIT
7.5
HIGH · CVSS 3.1 · EPSS 100% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2022-05-25.
Description
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.
Scoring
| CVSS | 7.5 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| EPSS | 100% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-125 |
| On CISA KEV | yes — remediate by 2022-05-25 |
| Public exploit | yes |
| Published | 2014-04-07 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | OpenSSL Information Disclosure Vulnerability |
|---|---|
| Added | 2022-05-04 |
| Due | 2022-05-25 |
| Vendor / product | OpenSSL / OpenSSL |
| Ransomware use | none reported |
Affected (35)
| Vendor | Product |
|---|---|
| broadcom | symantec messaging gateway |
| canonical | ubuntu linux |
| debian | debian linux |
| fedoraproject | fedora |
| filezilla-project | filezilla server |
| intellian | v100 |
| intellian | v100 firmware |
| intellian | v60 |
| intellian | v60 firmware |
| mitel | micollab |
| mitel | mivoice |
| openssl | openssl |
| opensuse | opensuse |
| redhat | enterprise linux desktop |
| redhat | enterprise linux server |
| redhat | enterprise linux server aus |
| redhat | enterprise linux server eus |
| redhat | enterprise linux server tus |
| redhat | enterprise linux workstation |
| redhat | gluster storage |
| redhat | storage |
| redhat | virtualization |
| ricon | s9922l |
| ricon | s9922l firmware |
| siemens | application processing engine |
| siemens | application processing engine firmware |
| siemens | cp 1543-1 |
| siemens | cp 1543-1 firmware |
| siemens | elan-8.2 |
| siemens | simatic s7-1500 |
| siemens | simatic s7-1500 firmware |
| siemens | simatic s7-1500t |
| siemens | simatic s7-1500t firmware |
| siemens | wincc open architecture |
| splunk | splunk |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | OpenSSL TLS Heartbeat Extension - 'Heartbleed' Information Leak (2) (DTLS Support) | 2014-04-24 |
| exploit-db | OpenSSL TLS Heartbeat Extension - 'Heartbleed' Information Leak (1) | 2014-04-10 |
| exploit-db | OpenSSL 1.0.1f TLS Heartbeat Extension - 'Heartbleed' Memory Disclosure (Multiple SSL/TLS Versions) | 2014-04-09 |
| exploit-db | OpenSSL TLS Heartbeat Extension - 'Heartbleed' Memory Disclosure | 2014-04-08 |
References
- http://advisories.mageia.org/MGASA-2014-0165.html
- http://blog.fox-it.com/2014/04/08/openssl-heartbleed-bug-live-blog/
- http://cogentdatahub.com/ReleaseNotes.html
- http://download.schneider-electric.com/files?p_Doc_Ref=SEVD%202014-119-01
- http://git.openssl.org/gitweb/?p=openssl.git%3Ba=commit%3Bh=96db9023b881d7cd9f379b0c154650d6c108e9a3
- http://heartbleed.com/
- http://lists.fedoraproject.org/pipermail/package-announce/2014-April/131221.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-April/131291.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136473.html
- http://lists.opensuse.org/opensuse-security-announce/2014-04/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2014-04/msg00005.html
- http://lists.opensuse.org/opensuse-updates/2014-04/msg00061.html
- http://marc.info/?l=bugtraq&m=139722163017074&w=2
- http://marc.info/?l=bugtraq&m=139757726426985&w=2
- http://marc.info/?l=bugtraq&m=139757819327350&w=2
- http://marc.info/?l=bugtraq&m=139757919027752&w=2
- http://marc.info/?l=bugtraq&m=139758572430452&w=2
- http://marc.info/?l=bugtraq&m=139765756720506&w=2
- http://marc.info/?l=bugtraq&m=139774054614965&w=2
- http://marc.info/?l=bugtraq&m=139774703817488&w=2
→ the Explorer · watch your stack · NVD