4.3
CVE-2014-3566
- EPSS 94.02%
- Veröffentlicht 15.10.2014 00:55:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
- Quelle secalert@redhat.com
- Teams Watchlist Login
- Unerledigt Login
The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Enterprise Linux Version5
Redhat ≫ Enterprise Linux Desktop Version6.0
Redhat ≫ Enterprise Linux Desktop Version7.0
Redhat ≫ Enterprise Linux Desktop Supplementary Version5.0
Redhat ≫ Enterprise Linux Desktop Supplementary Version6.0
Redhat ≫ Enterprise Linux Server Version6.0
Redhat ≫ Enterprise Linux Server Version7.0
Redhat ≫ Enterprise Linux Server Supplementary Version5.0
Redhat ≫ Enterprise Linux Server Supplementary Version6.0
Redhat ≫ Enterprise Linux Server Supplementary Version7.0
Redhat ≫ Enterprise Linux Workstation Version6.0
Redhat ≫ Enterprise Linux Workstation Version7.0
Redhat ≫ Enterprise Linux Workstation Supplementary Version6.0
Redhat ≫ Enterprise Linux Workstation Supplementary Version7.0
Novell ≫ Suse Linux Enterprise Desktop Version9.0
Novell ≫ Suse Linux Enterprise Desktop Version10.0
Novell ≫ Suse Linux Enterprise Desktop Version11.0
Novell ≫ Suse Linux Enterprise Desktop Version12.0
Novell ≫ Suse Linux Enterprise Software Development Kit Version11.0 Updatesp3
Novell ≫ Suse Linux Enterprise Software Development Kit Version12.0
Novell ≫ Suse Linux Enterprise Server Version11.0 Updatesp3
Novell ≫ Suse Linux Enterprise Server Version11.0 Updatesp3 SwPlatformvmware
Novell ≫ Suse Linux Enterprise Server Version12.0
Fedoraproject ≫ Fedora Version19
Fedoraproject ≫ Fedora Version20
Fedoraproject ≫ Fedora Version21
Debian ≫ Debian Linux Version7.0
Debian ≫ Debian Linux Version8.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 94.02% | 0.999 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 3.4 | 1.6 | 1.4 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N
|
nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:P/I:N/A:N
|