← Back to CVE List
Vulnerability Intelligence Report

CVE-2014-0224

OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive information, via a crafted TLS handshake, aka the "CCS Injection" vulnerability.

No Active Exploit Signals
CVSS Base Score
7.4
HIGH
EPSS Probability:95.33%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
openssl openssl all
redhat jboss_enterprise_application_platform 5.2.0, 6.2.3
redhat jboss_enterprise_web_platform 5.2.0
redhat jboss_enterprise_web_server 2.0.1
redhat storage 2.1
fedoraproject fedora 19, 20
opensuse opensuse 13.1, 13.2
redhat enterprise_linux 4, 5, 6.0
filezilla-project filezilla_server all
siemens application_processing_engine_firmware all
siemens application_processing_engine all
siemens cp1543-1_firmware all
siemens cp1543-1 all
siemens s7-1500_firmware all
siemens s7-1500 all
siemens rox_firmware all
siemens rox all
mariadb mariadb all
python python all
nodejs node.js all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
95.326%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityRed Hat, Inc. · Vendor · USA
Reserved2013-12-03T00:00:00
Published2014-06-05T21:00:00
Patch Date2014-06-05
Last Updated2024-08-06T09:05:39

LINK COPIED TO CLIPBOARD