← All CVEs

CVE-2014-0160

high · 7.5Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2022-05-04Remediation due 2022-05-25

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.

7.5
CVSS
100.0%
EPSS (exploit prob.)
100th
EPSS percentile
2014-04-07
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses

CWE-125

Affected products

VendorProductAffected versions
opensslopenssl>= 1.0.1, < 1.0.1g
filezilla-projectfilezilla_server< 0.9.44
siemensapplication_processing_engine_firmware2.0
siemensapplication_processing_engineall versions
siemenscp_1543-1_firmware1.1
siemenscp_1543-1all versions
siemenssimatic_s7-1500_firmware1.5
siemenssimatic_s7-1500all versions
siemenssimatic_s7-1500t_firmware1.5
siemenssimatic_s7-1500tall versions
siemenselan-8.2< 8.3.3
siemenswincc_open_architecture3.12
intellianv100_firmware1.20
intellianv100_firmware1.21
intellianv100_firmware1.24
intellianv100all versions
intellianv60_firmware1.15
intellianv60_firmware1.25
intellianv60all versions
mitelmicollab6.0
mitelmicollab7.0
mitelmicollab7.1
mitelmicollab7.2
mitelmicollab7.3
mitelmicollab7.3.0.104
mitelmivoice1.1.2.5
mitelmivoice1.1.3.3
mitelmivoice1.2.0.11
mitelmivoice1.3.2.2
mitelmivoice1.4.0.102
opensuseopensuse12.3
opensuseopensuse13.1
canonicalubuntu_linux12.04
canonicalubuntu_linux12.10
canonicalubuntu_linux13.10
fedoraprojectfedora19
fedoraprojectfedora20
redhatgluster_storage2.1
redhatstorage2.1
redhatvirtualization6.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2014-0160