← All CVEs

CVE-2014-0224

high · 7.4

OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive information, via a crafted TLS handshake, aka the "CCS Injection" vulnerability.

7.4
CVSS
95.3%
EPSS (exploit prob.)
100th
EPSS percentile
2014-06-05
Published

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Weaknesses

CWE-326

Affected products

VendorProductAffected versions
opensslopenssl< 0.9.8za
opensslopenssl>= 1.0.0, < 1.0.0m
opensslopenssl>= 1.0.1, < 1.0.1h
redhatjboss_enterprise_application_platform5.2.0
redhatjboss_enterprise_application_platform6.2.3
redhatjboss_enterprise_web_platform5.2.0
redhatjboss_enterprise_web_server2.0.1
redhatstorage2.1
fedoraprojectfedora19
fedoraprojectfedora20
opensuseopensuse13.1
opensuseopensuse13.2
redhatenterprise_linux4
redhatenterprise_linux5
redhatenterprise_linux6.0
filezilla-projectfilezilla_server< 0.9.45
siemensapplication_processing_engine_firmware< 2.0.2
siemensapplication_processing_engineall versions
siemenscp1543-1_firmware< 1.1.25
siemenscp1543-1all versions
siemenss7-1500_firmware< 1.6
siemenss7-1500all versions
siemensrox_firmware< 1.16.1
siemensroxall versions
mariadbmariadb>= 10.0.0, < 10.0.13
pythonpython>= 2.7.0, < 2.7.8
pythonpython>= 3.4.0, < 3.4.2
nodejsnode.js< 0.10.29

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2014-0224