SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2014-0160

OpenSSL Information Disclosure Vulnerability

KEVHIGH 7.5EPSS 100.0%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 25 May 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
100.00% probability · 100th percentile
CISA KEV
Listed 4 May 2022 · due 25 May 2022
Weakness
CWE-125
Affected
openssl/openssl · filezilla-project/filezilla server · siemens/application processing engine firmware · siemens/cp 1543-1 firmware · siemens/simatic s7-1500 firmware · siemens/simatic s7-1500t firmware · siemens/elan-8.2 · siemens/wincc open architecture · intellian/v100 firmware · intellian/v60 firmware · mitel/micollab · mitel/mivoice · opensuse/opensuse · canonical/ubuntu linux · fedoraproject/fedora · redhat/gluster storage · redhat/storage · redhat/virtualization · redhat/enterprise linux desktop · redhat/enterprise linux server · +8 more
Source
secalert@redhat.com

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2014-0160

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.