← Back to CVE List
Vulnerability Intelligence Report
OpenSSL Information Disclosure Vulnerability

CVE-2014-0160

The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.

CISA KEV Nuclei Template SSVC: Active Exploitation Automatable
CVSS Base Score
7.5
HIGH
Exploitability:3.9
Impact Score:3.6
EPSS Probability:100.00%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-125 ↗CWE-125 Out-of-bounds Read

Affected Products & Versions

Vendor Product Affected Versions
openssl openssl all
filezilla-project filezilla_server all
siemens application_processing_engine_firmware 2.0
siemens application_processing_engine all
siemens cp_1543-1_firmware 1.1
siemens cp_1543-1 all
siemens simatic_s7-1500_firmware 1.5
siemens simatic_s7-1500 all
siemens simatic_s7-1500t_firmware 1.5
siemens simatic_s7-1500t all
siemens elan-8.2 all
siemens wincc_open_architecture 3.12
intellian v100_firmware 1.20, 1.21, 1.24
intellian v100 all
intellian v60_firmware 1.15, 1.25
intellian v60 all
mitel micollab 6.0, 7.0, 7.1, 7.2, 7.3, 7.3.0.104
mitel mivoice 1.1.2.5, 1.1.3.3, 1.2.0.11, 1.3.2.2, 1.4.0.102
opensuse opensuse 12.3, 13.1
canonical ubuntu_linux 12.04, 12.10, 13.10
fedoraproject fedora 19, 20
redhat gluster_storage 2.1
redhat storage 2.1
redhat virtualization 6.0
redhat enterprise_linux_desktop 6.0
redhat enterprise_linux_server 6.0
redhat enterprise_linux_server_aus 6.5
redhat enterprise_linux_server_eus 6.5
redhat enterprise_linux_server_tus 6.5
redhat enterprise_linux_workstation 6.0
debian debian_linux 6.0, 7.0, 8.0
ricon s9922l_firmware 16.10.3\(3794\)
ricon s9922l 1.0
broadcom symantec_messaging_gateway 10.6.0, 10.6.1
splunk splunk all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
99.999%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityRed Hat, Inc. · Vendor · USA
Reserved2013-12-03T00:00:00
Published2014-04-07T00:00:00
Patch Date2014-04-07
Last Updated2025-10-22T00:05:38

LINK COPIED TO CLIPBOARD