7.4

CVE-2014-0224

Exploit

OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive information, via a crafted TLS handshake, aka the "CCS Injection" vulnerability.

Data is provided by the National Vulnerability Database (NVD)
OpenSSLOpenSSL Version < 0.9.8za
OpenSSLOpenSSL Version >= 1.0.0 < 1.0.0m
OpenSSLOpenSSL Version >= 1.0.1 < 1.0.1h
RedhatStorage Version2.1
FedoraprojectFedora Version19
FedoraprojectFedora Version20
OpensuseOpensuse Version13.1
OpensuseOpensuse Version13.2
RedhatEnterprise Linux Version4
RedhatEnterprise Linux Version5
RedhatEnterprise Linux Version6.0
Filezilla-projectFilezilla Server Version < 0.9.45
SiemensCp1543-1 Firmware Version < 1.1.25
   SiemensCp1543-1 Version-
SiemensS7-1500 Firmware Version < 1.6
   SiemensS7-1500 Version-
SiemensRox Firmware Version < 1.16.1
   SiemensRox Version-
MariadbMariadb Version >= 10.0.0 < 10.0.13
PythonPython Version >= 2.7.0 < 2.7.8
PythonPython Version >= 3.4.0 < 3.4.2
NodejsNode.Js Version < 0.10.29
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 92.69% 0.997
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.4 2.2 5.2
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
nvd@nist.gov 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:P/I:P/A:N
CWE-326 Inadequate Encryption Strength

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

http://seclists.org/fulldisclosure/2014/Dec/23
Third Party Advisory
Mailing List
http://www.securityfocus.com/archive/1/534161/100/0/threaded
Third Party Advisory
VDB Entry
Not Applicable
http://www.securitytracker.com/id/1031594
Third Party Advisory
VDB Entry
http://ccsinjection.lepidum.co.jp
Third Party Advisory
http://seclists.org/fulldisclosure/2014/Jun/38
Third Party Advisory
Mailing List
http://www.kb.cert.org/vuls/id/978508
Third Party Advisory
US Government Resource
http://www.securitytracker.com/id/1031032
Third Party Advisory
VDB Entry