CVE-2014-0160
high · 7.5Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
Apply updates per vendor instructions.
Added 2022-05-04Remediation due 2022-05-25
A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.
7.5
CVSS
100.0%
EPSS (exploit prob.)
100th
EPSS percentile
2014-04-07
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weaknesses
CWE-125
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| openssl | openssl | >= 1.0.1, < 1.0.1g |
| filezilla-project | filezilla_server | < 0.9.44 |
| siemens | application_processing_engine_firmware | 2.0 |
| siemens | application_processing_engine | all versions |
| siemens | cp_1543-1_firmware | 1.1 |
| siemens | cp_1543-1 | all versions |
| siemens | simatic_s7-1500_firmware | 1.5 |
| siemens | simatic_s7-1500 | all versions |
| siemens | simatic_s7-1500t_firmware | 1.5 |
| siemens | simatic_s7-1500t | all versions |
| siemens | elan-8.2 | < 8.3.3 |
| siemens | wincc_open_architecture | 3.12 |
| intellian | v100_firmware | 1.20 |
| intellian | v100_firmware | 1.21 |
| intellian | v100_firmware | 1.24 |
| intellian | v100 | all versions |
| intellian | v60_firmware | 1.15 |
| intellian | v60_firmware | 1.25 |
| intellian | v60 | all versions |
| mitel | micollab | 6.0 |
| mitel | micollab | 7.0 |
| mitel | micollab | 7.1 |
| mitel | micollab | 7.2 |
| mitel | micollab | 7.3 |
| mitel | micollab | 7.3.0.104 |
| mitel | mivoice | 1.1.2.5 |
| mitel | mivoice | 1.1.3.3 |
| mitel | mivoice | 1.2.0.11 |
| mitel | mivoice | 1.3.2.2 |
| mitel | mivoice | 1.4.0.102 |
| opensuse | opensuse | 12.3 |
| opensuse | opensuse | 13.1 |
| canonical | ubuntu_linux | 12.04 |
| canonical | ubuntu_linux | 12.10 |
| canonical | ubuntu_linux | 13.10 |
| fedoraproject | fedora | 19 |
| fedoraproject | fedora | 20 |
| redhat | gluster_storage | 2.1 |
| redhat | storage | 2.1 |
| redhat | virtualization | 6.0 |
Check a specific version with /api/v1/cve/match.
References
- http://advisories.mageia.org/MGASA-2014-0165.html
- http://blog.fox-it.com/2014/04/08/openssl-heartbleed-bug-live-blog/
- http://cogentdatahub.com/ReleaseNotes.html
- http://download.schneider-electric.com/files?p_Doc_Ref=SEVD%202014-119-01
- http://git.openssl.org/gitweb/?p=openssl.git%3Ba=commit%3Bh=96db9023b881d7cd9f379b0c154650d6c108e9a3
- http://heartbleed.com/
- http://lists.fedoraproject.org/pipermail/package-announce/2014-April/131221.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-April/131291.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136473.html
- http://lists.opensuse.org/opensuse-security-announce/2014-04/msg00004.html
- http://lists.opensuse.org/opensuse-security-announce/2014-04/msg00005.html
- http://lists.opensuse.org/opensuse-updates/2014-04/msg00061.html
- http://marc.info/?l=bugtraq&m=139722163017074&w=2
- http://marc.info/?l=bugtraq&m=139757726426985&w=2
- http://marc.info/?l=bugtraq&m=139757819327350&w=2
- http://marc.info/?l=bugtraq&m=139757919027752&w=2
- http://marc.info/?l=bugtraq&m=139758572430452&w=2
- http://marc.info/?l=bugtraq&m=139765756720506&w=2
- http://marc.info/?l=bugtraq&m=139774054614965&w=2
- http://marc.info/?l=bugtraq&m=139774703817488&w=2
- http://marc.info/?l=bugtraq&m=139808058921905&w=2
- http://marc.info/?l=bugtraq&m=139817685517037&w=2
- http://marc.info/?l=bugtraq&m=139817727317190&w=2
- http://marc.info/?l=bugtraq&m=139817782017443&w=2
- http://marc.info/?l=bugtraq&m=139824923705461&w=2
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2014-0160