{
    "id": "CVE-2014-0160",
    "published": "2014-04-07 22:55:03",
    "last_modified": "2026-06-17 00:02:24",
    "cvss_score": "7.5",
    "cvss_severity": "HIGH",
    "cvss_version": "3.1",
    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
    "cwe": "CWE-125",
    "description": "The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.",
    "epss_score": "0.99999",
    "epss_percentile": "0.99997",
    "kev": 1,
    "kev_due": "2022-05-25",
    "has_exploit": 1,
    "updated_at": "2026-09-26 18:19:13",
    "priority": {
        "rank": 1,
        "label": "Patch first",
        "why": "On CISA KEV — known exploited in the wild, due 2022-05-25."
    },
    "products": [
        {
            "vendor": "broadcom",
            "product": "symantec_messaging_gateway"
        },
        {
            "vendor": "canonical",
            "product": "ubuntu_linux"
        },
        {
            "vendor": "debian",
            "product": "debian_linux"
        },
        {
            "vendor": "fedoraproject",
            "product": "fedora"
        },
        {
            "vendor": "filezilla-project",
            "product": "filezilla_server"
        },
        {
            "vendor": "intellian",
            "product": "v100"
        },
        {
            "vendor": "intellian",
            "product": "v100_firmware"
        },
        {
            "vendor": "intellian",
            "product": "v60"
        },
        {
            "vendor": "intellian",
            "product": "v60_firmware"
        },
        {
            "vendor": "mitel",
            "product": "micollab"
        },
        {
            "vendor": "mitel",
            "product": "mivoice"
        },
        {
            "vendor": "openssl",
            "product": "openssl"
        },
        {
            "vendor": "opensuse",
            "product": "opensuse"
        },
        {
            "vendor": "redhat",
            "product": "enterprise_linux_desktop"
        },
        {
            "vendor": "redhat",
            "product": "enterprise_linux_server"
        },
        {
            "vendor": "redhat",
            "product": "enterprise_linux_server_aus"
        },
        {
            "vendor": "redhat",
            "product": "enterprise_linux_server_eus"
        },
        {
            "vendor": "redhat",
            "product": "enterprise_linux_server_tus"
        },
        {
            "vendor": "redhat",
            "product": "enterprise_linux_workstation"
        },
        {
            "vendor": "redhat",
            "product": "gluster_storage"
        },
        {
            "vendor": "redhat",
            "product": "storage"
        },
        {
            "vendor": "redhat",
            "product": "virtualization"
        },
        {
            "vendor": "ricon",
            "product": "s9922l"
        },
        {
            "vendor": "ricon",
            "product": "s9922l_firmware"
        },
        {
            "vendor": "siemens",
            "product": "application_processing_engine"
        },
        {
            "vendor": "siemens",
            "product": "application_processing_engine_firmware"
        },
        {
            "vendor": "siemens",
            "product": "cp_1543-1"
        },
        {
            "vendor": "siemens",
            "product": "cp_1543-1_firmware"
        },
        {
            "vendor": "siemens",
            "product": "elan-8.2"
        },
        {
            "vendor": "siemens",
            "product": "simatic_s7-1500"
        },
        {
            "vendor": "siemens",
            "product": "simatic_s7-1500_firmware"
        },
        {
            "vendor": "siemens",
            "product": "simatic_s7-1500t"
        },
        {
            "vendor": "siemens",
            "product": "simatic_s7-1500t_firmware"
        },
        {
            "vendor": "siemens",
            "product": "wincc_open_architecture"
        },
        {
            "vendor": "splunk",
            "product": "splunk"
        }
    ],
    "kev_detail": {
        "cve_id": "CVE-2014-0160",
        "date_added": "2022-05-04",
        "due_date": "2022-05-25",
        "vendor": "OpenSSL",
        "product": "OpenSSL",
        "name": "OpenSSL Information Disclosure Vulnerability",
        "ransomware": 0
    },
    "exploits": [
        {
            "source": "exploit-db",
            "ref_id": "32998",
            "title": "OpenSSL TLS Heartbeat Extension - 'Heartbleed' Information Leak (2) (DTLS Support)",
            "date": "2014-04-24",
            "url": "https://www.exploit-db.com/exploits/32998"
        },
        {
            "source": "exploit-db",
            "ref_id": "32791",
            "title": "OpenSSL TLS Heartbeat Extension - 'Heartbleed' Information Leak (1)",
            "date": "2014-04-10",
            "url": "https://www.exploit-db.com/exploits/32791"
        },
        {
            "source": "exploit-db",
            "ref_id": "32764",
            "title": "OpenSSL 1.0.1f TLS Heartbeat Extension - 'Heartbleed' Memory Disclosure (Multiple SSL/TLS Versions)",
            "date": "2014-04-09",
            "url": "https://www.exploit-db.com/exploits/32764"
        },
        {
            "source": "exploit-db",
            "ref_id": "32745",
            "title": "OpenSSL TLS Heartbeat Extension - 'Heartbleed' Memory Disclosure",
            "date": "2014-04-08",
            "url": "https://www.exploit-db.com/exploits/32745"
        }
    ],
    "refs_list": [
        "http://advisories.mageia.org/MGASA-2014-0165.html",
        "http://blog.fox-it.com/2014/04/08/openssl-heartbleed-bug-live-blog/",
        "http://cogentdatahub.com/ReleaseNotes.html",
        "http://download.schneider-electric.com/files?p_Doc_Ref=SEVD%202014-119-01",
        "http://git.openssl.org/gitweb/?p=openssl.git%3Ba=commit%3Bh=96db9023b881d7cd9f379b0c154650d6c108e9a3",
        "http://heartbleed.com/",
        "http://lists.fedoraproject.org/pipermail/package-announce/2014-April/131221.html",
        "http://lists.fedoraproject.org/pipermail/package-announce/2014-April/131291.html",
        "http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136473.html",
        "http://lists.opensuse.org/opensuse-security-announce/2014-04/msg00004.html",
        "http://lists.opensuse.org/opensuse-security-announce/2014-04/msg00005.html",
        "http://lists.opensuse.org/opensuse-updates/2014-04/msg00061.html",
        "http://marc.info/?l=bugtraq&m=139722163017074&w=2",
        "http://marc.info/?l=bugtraq&m=139757726426985&w=2",
        "http://marc.info/?l=bugtraq&m=139757819327350&w=2",
        "http://marc.info/?l=bugtraq&m=139757919027752&w=2",
        "http://marc.info/?l=bugtraq&m=139758572430452&w=2",
        "http://marc.info/?l=bugtraq&m=139765756720506&w=2",
        "http://marc.info/?l=bugtraq&m=139774054614965&w=2",
        "http://marc.info/?l=bugtraq&m=139774703817488&w=2",
        "http://marc.info/?l=bugtraq&m=139808058921905&w=2",
        "http://marc.info/?l=bugtraq&m=139817685517037&w=2",
        "http://marc.info/?l=bugtraq&m=139817727317190&w=2",
        "http://marc.info/?l=bugtraq&m=139817782017443&w=2",
        "http://marc.info/?l=bugtraq&m=139824923705461&w=2"
    ]
}