← All CVEs

CVE-2014-3566

low · 3.4

The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.

3.4
CVSS
100.0%
EPSS (exploit prob.)
100th
EPSS percentile
2014-10-15
Published

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N

Weaknesses

CWE-310CWE-329

Affected products

VendorProductAffected versions
redhatenterprise_linux5
redhatenterprise_linux_desktop6.0
redhatenterprise_linux_desktop7.0
redhatenterprise_linux_desktop_supplementary5.0
redhatenterprise_linux_desktop_supplementary6.0
redhatenterprise_linux_server6.0
redhatenterprise_linux_server7.0
redhatenterprise_linux_server_supplementary5.0
redhatenterprise_linux_server_supplementary6.0
redhatenterprise_linux_server_supplementary7.0
redhatenterprise_linux_workstation6.0
redhatenterprise_linux_workstation7.0
redhatenterprise_linux_workstation_supplementary6.0
redhatenterprise_linux_workstation_supplementary7.0
ibmaix5.3
ibmaix6.1
ibmaix7.1
applemac_os_x<= 10.10.1
mageiamageia3.0
mageiamageia4.0
novellsuse_linux_enterprise_desktop9.0
novellsuse_linux_enterprise_desktop10.0
novellsuse_linux_enterprise_desktop11.0
novellsuse_linux_enterprise_desktop12.0
novellsuse_linux_enterprise_software_development_kit11.0
novellsuse_linux_enterprise_software_development_kit12.0
novellsuse_linux_enterprise_server11.0
novellsuse_linux_enterprise_server11.0
novellsuse_linux_enterprise_server12.0
opensuseopensuse12.3
opensuseopensuse13.1
fedoraprojectfedora19
fedoraprojectfedora20
fedoraprojectfedora21
opensslopenssl0.9.8
opensslopenssl0.9.8a
opensslopenssl0.9.8b
opensslopenssl0.9.8c
opensslopenssl0.9.8d
opensslopenssl0.9.8e

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2014-3566