CVE-2014-0160
גבוהה 7.5 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- OpenSSL Information Disclosure Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.
מדדים
- CVSS 3.1
-
7.5 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - EPSS — סבירות ניצול
- 100% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-125
מוצרים מושפעים
openssl: openssl; filezilla-project: filezilla server; siemens: application processing engine firmware; siemens: application processing engine; siemens: cp 1543-1 firmware; siemens: cp 1543-1; siemens: simatic s7-1500 firmware; siemens: simatic s7-1500; siemens: simatic s7-1500t firmware; siemens: simatic s7-1500t; siemens: elan-8.2; siemens: wincc open architecture; intellian: v100 firmware; intellian: v100; intellian: v60 firmware
קישורים
- http://www.openssl.org/news/secadv_20140407.txt Broken LinkVendor Advisory
- http://www.openssl.org/news/secadv_20140407.txt Broken LinkVendor Advisory
- http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html PatchThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/opensslheartbleedcve-2014-01… PatchThird Party Advisory
- https://lists.apache.org/thread.html/ba661b0edd913b39ff129a32d855620dd861883ad… Mailing ListPatchThird Party Advisory
- https://lists.apache.org/thread.html/f8e0814e11c7f21f42224b6de111cb3f5e5ab5c15… Mailing ListPatchThird Party Advisory
- https://lists.apache.org/thread.html/re3b72cbb13e1dfe85c4a06959a3b6ca6d939b407… Mailing ListPatchThird Party Advisory
- https://lists.apache.org/thread.html/rf8e8c091182b45daa50d3557cad9b10bb4198e3f… Mailing ListPatchThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html PatchThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/opensslheartbleedcve-2014-01… PatchThird Party Advisory