CVE-2014-0160
OpenSSL: Information Disclosure
As of , CVE-2014-0160 in OpenSSL is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.
- Exploited
- Yes: CISA listed it on 4 May 2022
- US federal deadline
- 25 May 202221 days after CISA listed it. US federal civilian agencies must fix it by then.
- Used in ransomware campaigns
- Not known to CISA
- EPSS score
- 0.99Higher than 99% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
- EPSS when listed
- 0.96 on 4 May 2022EPSS on the day CISA listed it.
- Public exploit
- 2 Metasploit modules and 4 Exploit-DB entries (4 verified)
- Fix
- No vendor link in CISA's entry
What CISA says to do
Apply updates per vendor instructions.
CISA's required action
What the flaw is
The TLS and DTLS implementations in OpenSSL do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information.
CISA's description
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.
The CVE record's description, from redhat
- CVE published
- 7 April 2014
- Assigned by
- redhat
- CVSS
- 7.5 High (CVSS 3.1, from CISA-ADP)
- CWE-125
- Out-of-bounds Read
- CISA SSVC, exploitation
- active
- CISA SSVC, automatable
- yes
- CISA SSVC, technical impact
- partial
Timeline
- The CVE record was published.
- Exploit-DB published an exploit (EDB-ID 32745).
- Exploit-DB published an exploit (EDB-ID 32764).
- Exploit-DB published an exploit (EDB-ID 32791).
- Exploit-DB published an exploit (EDB-ID 32998).
- CISA added it to its list of exploited vulnerabilities.
- The US federal deadline to fix it.
Public exploits
Facts from Metasploit's module list and Exploit-DB's index; we never copy exploit code.
- Metasploit: OpenSSL Heartbeat (Heartbleed) Information Leakauxiliary module, rank normal
- Metasploit: OpenSSL Heartbeat (Heartbleed) Client Memory Exposureauxiliary module, rank normal
- Exploit-DB: OpenSSL TLS Heartbeat Extension - 'Heartbleed' Information Leak (2) (DTLS Support)EDB-ID 32998, verified by Exploit-DB, 24 April 2014
- Exploit-DB: OpenSSL TLS Heartbeat Extension - 'Heartbleed' Information Leak (1)EDB-ID 32791, verified by Exploit-DB, 10 April 2014
- Exploit-DB: OpenSSL 1.0.1f TLS Heartbeat Extension - 'Heartbleed' Memory Disclosure (Multiple SSL/TLS Versions)EDB-ID 32764, verified by Exploit-DB, 9 April 2014
- Exploit-DB: OpenSSL TLS Heartbeat Extension - 'Heartbleed' Memory DisclosureEDB-ID 32745, verified by Exploit-DB, 8 April 2014
Read further
- CVE recordcve.org
- NVD entrynvd.nist.gov
- CISA's catalogcisa.gov
- EPSS for this CVEapi.first.org