infosecramblings

Actively exploited — CISA Known Exploited Vulnerabilities (KEV) Catalog

CISA has confirmed this vulnerability is being exploited in the wild as of May 4, 2022. Recommended action: Apply updates per vendor instructions.

Federal remediation deadline (BOD 22-01): May 25, 2022 — a useful urgency reference even outside federal agencies.

CVE-2014-0160

High7.5

The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.

Published
April 7, 2014
Last modified
June 17, 2026
CVSS v3
7.5 / 10
CVSS v2
5 / 10
EPSS
100.00%
100th percentile
100.00% probability of exploitation in the next 30 days, per FIRST.org's EPSS model — higher than 100% of all scored CVEs.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Weakness Type

  • CWE-125

Affected Products

  • cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
  • cpe:2.3:a:filezilla-project:filezilla_server:*:*:*:*:*:*:*:*
  • cpe:2.3:o:siemens:application_processing_engine_firmware:2.0:*:*:*:*:*:*:*
  • cpe:2.3:h:siemens:application_processing_engine:-:*:*:*:*:*:*:*
  • cpe:2.3:o:siemens:cp_1543-1_firmware:1.1:*:*:*:*:*:*:*
  • cpe:2.3:h:siemens:cp_1543-1:-:*:*:*:*:*:*:*
  • cpe:2.3:o:siemens:simatic_s7-1500_firmware:1.5:*:*:*:*:*:*:*
  • cpe:2.3:h:siemens:simatic_s7-1500:-:*:*:*:*:*:*:*
  • cpe:2.3:o:siemens:simatic_s7-1500t_firmware:1.5:*:*:*:*:*:*:*
  • cpe:2.3:h:siemens:simatic_s7-1500t:-:*:*:*:*:*:*:*
  • cpe:2.3:a:siemens:elan-8.2:*:*:*:*:*:*:*:*
  • cpe:2.3:a:siemens:wincc_open_architecture:3.12:*:*:*:*:*:*:*
  • cpe:2.3:o:intellian:v100_firmware:1.20:*:*:*:*:*:*:*
  • cpe:2.3:o:intellian:v100_firmware:1.21:*:*:*:*:*:*:*
  • cpe:2.3:o:intellian:v100_firmware:1.24:*:*:*:*:*:*:*
  • cpe:2.3:h:intellian:v100:-:*:*:*:*:*:*:*
  • cpe:2.3:o:intellian:v60_firmware:1.15:*:*:*:*:*:*:*
  • cpe:2.3:o:intellian:v60_firmware:1.25:*:*:*:*:*:*:*
  • cpe:2.3:h:intellian:v60:-:*:*:*:*:*:*:*
  • cpe:2.3:a:mitel:micollab:6.0:*:*:*:*:*:*:*
  • cpe:2.3:a:mitel:micollab:7.0:*:*:*:*:*:*:*
  • cpe:2.3:a:mitel:micollab:7.1:*:*:*:*:*:*:*
  • cpe:2.3:a:mitel:micollab:7.2:*:*:*:*:*:*:*
  • cpe:2.3:a:mitel:micollab:7.3:*:*:*:*:*:*:*
  • cpe:2.3:a:mitel:micollab:7.3.0.104:*:*:*:*:*:*:*
  • cpe:2.3:a:mitel:mivoice:1.1.2.5:*:*:*:*:lync:*:*
  • cpe:2.3:a:mitel:mivoice:1.1.3.3:*:*:*:*:skype_for_business:*:*
  • cpe:2.3:a:mitel:mivoice:1.2.0.11:*:*:*:*:skype_for_business:*:*
  • cpe:2.3:a:mitel:mivoice:1.3.2.2:*:*:*:*:skype_for_business:*:*
  • cpe:2.3:a:mitel:mivoice:1.4.0.102:*:*:*:*:skype_for_business:*:*
  • cpe:2.3:o:opensuse:opensuse:12.3:*:*:*:*:*:*:*
  • cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*
  • cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*
  • cpe:2.3:o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*
  • cpe:2.3:o:canonical:ubuntu_linux:13.10:*:*:*:*:*:*:*
  • cpe:2.3:o:fedoraproject:fedora:19:*:*:*:*:*:*:*
  • cpe:2.3:o:fedoraproject:fedora:20:*:*:*:*:*:*:*
  • cpe:2.3:a:redhat:gluster_storage:2.1:*:*:*:*:*:*:*
  • cpe:2.3:a:redhat:storage:2.1:*:*:*:*:*:*:*
  • cpe:2.3:a:redhat:virtualization:6.0:*:*:*:*:*:*:*
  • cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
  • cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
  • cpe:2.3:o:redhat:enterprise_linux_server_aus:6.5:*:*:*:*:*:*:*
  • cpe:2.3:o:redhat:enterprise_linux_server_eus:6.5:*:*:*:*:*:*:*
  • cpe:2.3:o:redhat:enterprise_linux_server_tus:6.5:*:*:*:*:*:*:*
  • cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*
  • cpe:2.3:o:debian:debian_linux:6.0:*:*:*:*:*:*:*
  • cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
  • cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
  • cpe:2.3:o:ricon:s9922l_firmware:16.10.3\(3794\):*:*:*:*:*:*:*
  • cpe:2.3:h:ricon:s9922l:1.0:*:*:*:*:*:*:*
  • cpe:2.3:a:broadcom:symantec_messaging_gateway:10.6.0:*:*:*:*:*:*:*
  • cpe:2.3:a:broadcom:symantec_messaging_gateway:10.6.1:*:*:*:*:*:*:*
  • cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*

References

Data sourced from the National Vulnerability Database, CISA KEV Catalog, and FIRST.org EPSS. View on NVD →