7.5

CVE-2014-0160

Warning
Exploit

The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.

Data is provided by the National Vulnerability Database (NVD)
OpenSSLOpenSSL Version >= 1.0.1 < 1.0.1g
Filezilla-projectFilezilla Server Version < 0.9.44
SiemensCp 1543-1 Firmware Version1.1
   SiemensCp 1543-1 Version-
SiemensSimatic S7-1500 Firmware Version1.5
   SiemensSimatic S7-1500 Version-
SiemensSimatic S7-1500t Firmware Version1.5
   SiemensSimatic S7-1500t Version-
SiemensElan-8.2 Version < 8.3.3
IntellianV100 Firmware Version1.20
   IntellianV100 Version-
IntellianV100 Firmware Version1.21
   IntellianV100 Version-
IntellianV100 Firmware Version1.24
   IntellianV100 Version-
IntellianV60 Firmware Version1.15
   IntellianV60 Version-
IntellianV60 Firmware Version1.25
   IntellianV60 Version-
MitelMicollab Version6.0
MitelMicollab Version7.0
MitelMicollab Version7.1
MitelMicollab Version7.2
MitelMicollab Version7.3
MitelMicollab Version7.3.0.104
MitelMivoice Version1.1.2.5 SwPlatformlync
MitelMivoice Version1.1.3.3 SwPlatformskype_for_business
MitelMivoice Version1.2.0.11 SwPlatformskype_for_business
MitelMivoice Version1.3.2.2 SwPlatformskype_for_business
MitelMivoice Version1.4.0.102 SwPlatformskype_for_business
OpensuseOpensuse Version12.3
OpensuseOpensuse Version13.1
CanonicalUbuntu Linux Version12.04 SwEditionesm
CanonicalUbuntu Linux Version12.10
CanonicalUbuntu Linux Version13.10
FedoraprojectFedora Version19
FedoraprojectFedora Version20
RedhatGluster Storage Version2.1
RedhatStorage Version2.1
RedhatVirtualization Version6.0
DebianDebian Linux Version6.0
DebianDebian Linux Version7.0
DebianDebian Linux Version8.0
SplunkSplunk SwEditionenterprise Version >= 6.0.0 < 6.0.3

04.05.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog

OpenSSL Information Disclosure Vulnerability

Vulnerability

The TLS and DTLS implementations in OpenSSL do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information.

Description

Apply updates per vendor instructions.

Required actions
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 94.48% 1
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
134c704f-9b21-4f2e-91b3-4a467353bcc0 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-125 Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

http://marc.info/?l=bugtraq&m=142660345230545&w=2
Third Party Advisory
Mailing List
http://seclists.org/fulldisclosure/2014/Dec/23
Third Party Advisory
Mailing List
http://www.securityfocus.com/archive/1/534161/100/0/threaded
Third Party Advisory
Broken Link
VDB Entry
Not Applicable
http://secunia.com/advisories/57836
Third Party Advisory
Broken Link
http://secunia.com/advisories/57966
Third Party Advisory
Broken Link
http://secunia.com/advisories/57968
Third Party Advisory
Broken Link
http://marc.info/?l=bugtraq&m=140752315422991&w=2
Third Party Advisory
Mailing List
http://heartbleed.com/
Third Party Advisory
http://marc.info/?l=bugtraq&m=139722163017074&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=139757726426985&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=139757819327350&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=139757919027752&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=139758572430452&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=139765756720506&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=139774054614965&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=139774703817488&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=139808058921905&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=139817685517037&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=139817727317190&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=139817782017443&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=139824923705461&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=139824993005633&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=139833395230364&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=139835815211508&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=139835844111589&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=139836085512508&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=139842151128341&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=139843768401936&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=139869720529462&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=139869891830365&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=139889113431619&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=139889295732144&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=139905202427693&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=139905243827825&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=139905295427946&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=139905351928096&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=139905405728262&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=139905458328378&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=139905653828999&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=139905868529690&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=140015787404650&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=140075368411126&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=140724451518351&w=2
Third Party Advisory
Mailing List
http://marc.info/?l=bugtraq&m=141287864628122&w=2
Third Party Advisory
Mailing List
http://seclists.org/fulldisclosure/2014/Apr/109
Third Party Advisory
Mailing List
http://seclists.org/fulldisclosure/2014/Apr/173
Third Party Advisory
Mailing List
http://seclists.org/fulldisclosure/2014/Apr/190
Third Party Advisory
Mailing List
http://seclists.org/fulldisclosure/2014/Apr/90
Third Party Advisory
Mailing List
http://seclists.org/fulldisclosure/2014/Apr/91
Third Party Advisory
Mailing List
http://secunia.com/advisories/57347
Third Party Advisory
Broken Link
http://secunia.com/advisories/57483
Third Party Advisory
Broken Link
http://secunia.com/advisories/57721
Third Party Advisory
Broken Link
http://secunia.com/advisories/59139
Third Party Advisory
Broken Link
http://secunia.com/advisories/59243
Third Party Advisory
Broken Link
http://secunia.com/advisories/59347
Third Party Advisory
Broken Link
http://www.debian.org/security/2014/dsa-2896
Third Party Advisory
Mailing List
http://www.exploit-db.com/exploits/32745
Third Party Advisory
Exploit
VDB Entry
http://www.exploit-db.com/exploits/32764
Third Party Advisory
Exploit
VDB Entry
http://www.kb.cert.org/vuls/id/720951
Third Party Advisory
US Government Resource
http://www.securityfocus.com/bid/66690
Third Party Advisory
Broken Link
VDB Entry
http://www.securitytracker.com/id/1030026
Third Party Advisory
Broken Link
VDB Entry
http://www.securitytracker.com/id/1030074
Third Party Advisory
Broken Link
VDB Entry
http://www.securitytracker.com/id/1030077
Third Party Advisory
Broken Link
VDB Entry
http://www.securitytracker.com/id/1030078
Third Party Advisory
Broken Link
VDB Entry
http://www.securitytracker.com/id/1030079
Third Party Advisory
Broken Link
VDB Entry
http://www.securitytracker.com/id/1030080
Third Party Advisory
Broken Link
VDB Entry
http://www.securitytracker.com/id/1030081
Third Party Advisory
Broken Link
VDB Entry
http://www.securitytracker.com/id/1030082
Third Party Advisory
Broken Link
VDB Entry
http://www.us-cert.gov/ncas/alerts/TA14-098A
Third Party Advisory
US Government Resource
https://bugzilla.redhat.com/show_bug.cgi?id=1084875
Third Party Advisory
Issue Tracking