SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2014-3566

The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.

LOW 3.4EPSS 100.0%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 100.0%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.

Description

The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.

CVSS 3.1
3.4 LOWCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N
EPSS
100.00% probability · 100th percentile
CISA KEV
Not listed
Weakness
CWE-310, CWE-329
Affected
redhat/enterprise linux · redhat/enterprise linux desktop · redhat/enterprise linux desktop supplementary · redhat/enterprise linux server · redhat/enterprise linux server supplementary · redhat/enterprise linux workstation · redhat/enterprise linux workstation supplementary · ibm/aix · apple/mac os x · mageia/mageia · novell/suse linux enterprise desktop · novell/suse linux enterprise software development kit · novell/suse linux enterprise server · opensuse/opensuse · fedoraproject/fedora · openssl/openssl · ibm/vios · netbsd/netbsd · debian/debian linux · oracle/database
Source
secalert@redhat.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.