← לוח פגיעויות

CVE-2014-0160

גבוהה 7.5 מנוצלת בשטח (KEV)

ניצול פעיל מאומת — קטלוג CISA KEV

שם
OpenSSL Information Disclosure Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply updates per vendor instructions.

תיאור (מקור, אנגלית)

The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.

מדדים

CVSS 3.1
7.5 (HIGH) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS — סבירות ניצול
100% (אחוזון 100) נכון ל-24/7/2026
CWE
CWE-125

מוצרים מושפעים

openssl: openssl; filezilla-project: filezilla server; siemens: application processing engine firmware; siemens: application processing engine; siemens: cp 1543-1 firmware; siemens: cp 1543-1; siemens: simatic s7-1500 firmware; siemens: simatic s7-1500; siemens: simatic s7-1500t firmware; siemens: simatic s7-1500t; siemens: elan-8.2; siemens: wincc open architecture; intellian: v100 firmware; intellian: v100; intellian: v60 firmware

קישורים