SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2014-0224

OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL…

HIGH 7.4EPSS 95.3%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 95.3%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.

Description

OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive information, via a crafted TLS handshake, aka the "CCS Injection" vulnerability.

CVSS 3.1
7.4 HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS
95.33% probability · 100th percentile
CISA KEV
Not listed
Weakness
CWE-326
Affected
openssl/openssl · redhat/jboss enterprise application platform · redhat/jboss enterprise web platform · redhat/jboss enterprise web server · redhat/storage · fedoraproject/fedora · opensuse/opensuse · redhat/enterprise linux · filezilla-project/filezilla server · siemens/application processing engine firmware · siemens/cp1543-1 firmware · siemens/s7-1500 firmware · siemens/rox firmware · mariadb/mariadb · python/python · nodejs/node.js
Source
secalert@redhat.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.