CVE-2014-0160
published 2014-04-07CVE-2014-0160: The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to…
PriorityP190high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2022-05-25
Exploited in the wild
EPSS
100.00%
100.0th percentile
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.
Affected
125 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| broadcom | symantec_messaging_gateway | — | — |
| broadcom | symantec_messaging_gateway | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| cisco | asa | — | — |
| cisco | telepresence_system_mxp_series | — | — |
| cisco | telepresence_tc_and_te | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | openssl | < openssl 1.0.1g-1 (bookworm) | openssl 1.0.1g-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| filezilla-project | filezilla_server | < 0.9.44 | 0.9.44 |
| hp | integrated_lights-out_2_firmware | <= 2.23 | — |
| hp | integrated_lights-out_2_firmware | — | — |
| hp | integrated_lights-out_2_firmware | — | — |
| hp | integrated_lights-out_2_firmware | — | — |
| hp | integrated_lights-out_2_firmware | — | — |
| hp | integrated_lights-out_2_firmware | — | — |
| hp | integrated_lights-out_2_firmware | — | — |
| hp | integrated_lights-out_2_firmware | — | — |
| hp | integrated_lights-out_2_firmware | — | — |
Detection & IOCsextracted from sources · hover to see the quote
snort↗
1059406 SSL OpenSSL TLS DTLS Heartbeat Information Disclosure -1 (CVE-2014-0160, Heartbleed)
snort↗
1059407 SSL OpenSSL TLS DTLS Heartbeat Information Disclosure -2 (CVE-2014-0160, Heartbleed)
- →Monitor SSL/TLS traffic for malformed or oversized heartbeat packets — each exploit request can leak up to 64KB of server memory per request, which may appear as anomalously large TLS heartbeat responses. ↗
- →Watch for VPN authentication events following Heartbleed probe activity — attackers in the CHS breach used credentials harvested via Heartbleed to authenticate to VPN and move laterally. ↗
- ·Crafted TLS heartbeat traffic from CVE-2014-0160 vulnerability-assessment tools can also trigger denial-of-service conditions in unrelated products (e.g., IBM WebSphere Application Server), potentially causing false-positive attribution during scanning. ↗
- ·Network-based IPS signatures detect exploit attempts but are not a substitute for patching; unpatched systems may remain exploitable even in environments with IPS deployed. ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vulncheck7.5HIGH
cisa7.5HIGH
vendor_apache7.5HIGH
vendor_cisco7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu1.9LOW
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
OpenSSL Information Disclosure Vulnerability
cisa·2022-05-04·CVSS 7.5
CVE-2014-0160 [HIGH] CWE-125 OpenSSL Information Disclosure Vulnerability
Vulnerability: OpenSSL Information Disclosure Vulnerability
Affected: OpenSSL OpenSSL
The TLS and DTLS implementations in OpenSSL do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2014-0160
Remediation Due Date: 2022-05-25
CISA ICS
Unified Automation OPC SDK OpenSSL Vulnerability
cisa_ics·2018-09-06
Unified Automation OPC SDK OpenSSL Vulnerability
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Unified Automation OPC SDK OpenSSL Vulnerability
Last RevisedSeptember 06, 2018
Alert CodeICSA-14-135-04
## OVERVIEW
On April 09, 2014, Unified Automation GmbH announced that its OPC UA Software Development Kits (SDKs) for Windows included vulnerable OpenSSL libraries. HTTPS support is disabled by default in Unified Automation SDK products. However if HTTPS is used, Unified Automation recommends replacing the OpenSSL library with a current version (1.01.g or later) to mitigate this vulnerability.
This vulnerability could be exploited remotely. Exploits that target this vulnerab
CISA ICS
Digi International OpenSSL Vulnerability
cisa_ics·2018-09-06
Digi International OpenSSL Vulnerability
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Digi International OpenSSL Vulnerability
Last RevisedSeptember 06, 2018
Alert CodeICSA-14-128-01
## OVERVIEW
Digi International has identified five products that are vulnerable to the OpenSSL Heartbleed bug. Digi International has produced downloadable firmware upgrade versions that mitigate this vulnerability.
This vulnerability could be exploited remotely. Exploits that target this vulnerability are known to be publicly available.
## AFFECTED PRODUCTS
The following Digi International products are affected:
- ConnectPort LTS,
- ConnectPort X2e,
- Digi Embedded Linux 5.9,
CISA ICS
Schneider Electric Wonderware Intelligence Security Patch for OpenSSL Vulnerability
cisa_ics·2018-08-27
Schneider Electric Wonderware Intelligence Security Patch for OpenSSL Vulnerability
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Schneider Electric Wonderware Intelligence Security Patch for OpenSSL Vulnerability
Last RevisedAugust 27, 2018
Alert CodeICSA-14-135-02
## OVERVIEW
Schneider Electric Wonderware’s Cyber Security Team has identified an OpenSSL Heartbleed vulnerability in the Wonderware Intelligence application, caused by a third-party component. Schneider Electric Wonderware has produced a patch that mitigates this vulnerability.
This vulnerability could be exploited remotely. Exploits that target this vulnerability are known to be publicly available.
## AFFECTED PRODUCTS
The latest release o
CISA ICS
Certec atvise scada OpenSSL Heartbleed Vulnerability
cisa_ics·2018-08-23
Certec atvise scada OpenSSL Heartbleed Vulnerability
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Certec atvise scada OpenSSL Heartbleed Vulnerability
Last RevisedAugust 23, 2018
Alert CodeICSA-14-114-01
## OVERVIEW
Researcher Bob Radvanovsky of Infracritical has notified NCCIC/ICS-CERT that Certec has released new libraries that mitigate the OpenSSL Heartbleed vulnerability in atvise scada.
This vulnerability could be exploited remotely. Exploits that target the OpenSSL Heartbleed vulnerability are known to be publicly available.
## AFFECTED PRODUCTS
Certec reports that the vulnerability affects the following versions of atvise scada:
- atvise scada Versions 2.3 and abo
CISA ICS
Advantech EKI Vulnerabilities (Update B)
cisa_ics·2015-12-15
Advantech EKI Vulnerabilities (Update B)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Advantech EKI Vulnerabilities (Update B)
Last RevisedAugust 23, 2018
Alert CodeICSA-15-344-01B
## OVERVIEW
This updated advisory is a follow-up to the updated advisory titled ICSA-15-344-01A Advantech EKI Vulnerabilities that was published December 15, 2015, on the NCCIC/ICS-CERT web site.
## --------- Begin Update B Part 1 of 3 --------
HD Moore of Rapid7 identified several vulnerabilities in Advantech’s EKI. Advantech has released updated firmware to mitigate these vulnerabilities.
## --------- End Update B Part 1 of 3 --------
These vulnerabilities could be exploited remo
CISA ICS
ABB Relion 650 Series OpenSSL Vulnerability (Update A)
cisa_ics·2014-05-06
ABB Relion 650 Series OpenSSL Vulnerability (Update A)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
ABB Relion 650 Series OpenSSL Vulnerability (Update A)
Last RevisedSeptember 06, 2018
Alert CodeICSA-14-126-01A
## OVERVIEW
## --------- Begin Update A Part 1 of 2--------
This updated advisory is a follow-up to the original advisory titled ICSA-14-126-01 ABB Relion 650 Series OpenSSL Vulnerability, that was published May 06, 2014, on the NCCIC/ICS-CERT web site.
ABB has identified an OpenSSL vulnerability in its Relion 650 series application and has issued maintenance Release 650 series Ver 1.3.0.1 to mitigate this vulnerability.
## --------- End Update A Part 1 of 2 -------
Cisco
Multiple Vulnerabilities in Cisco TelePresence System MXP Series
vendor_cisco·2014-04-30·CVSS 7.5
CVE-2014-2156 [HIGH] CWE-399 Multiple Vulnerabilities in Cisco TelePresence System MXP Series
Multiple Vulnerabilities in Cisco TelePresence System MXP Series
Cisco TelePresence System MXP Series Software contains the following vulnerabilities:
Three SIP denial of service vulnerabilities
Three H.225 denial of service vulnerabilities
Successful exploitation of these vulnerabilities may allow an attacker to cause system instability and the affected system to reload.
Note: This security advisory does not provide information about the OpenSSL TLS Heartbeat Read Overrun Vulnerability identified by CVE-2014-0160 (also known as Heartbleed). For additional information regarding Cisco products affected by the Heartbleed vulnerability, refer to the Cisco Security Advisory available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-
Cisco
Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
vendor_cisco·2014-04-30·CVSS 7.5
CVE-2014-2162 [HIGH] CWE-119 Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
Cisco TelePresence TC and TE Software are affected by the following vulnerabilities:
Six Session Initiation Protocol (SIP) denial of service vulnerabilities
Cisco TelePresence TC and TE Software DNS Buffer Overflow Vulnerability
Cisco TelePresence TC and TE Software Input Validation Vulnerability
Cisco TelePresence TC and TE Software tshell Command Injection Vulnerability
Cisco TelePresence TC and TE Software Heap Overflow Vulnerability
Cisco TelePresence TC and TE Software U-Boot Buffer Overflow Vulnerability
Cisco TelePresence TC and TE Software Unauthenticated Serial Port Access Vulnerability
Cisco TelePresence TC H.225 Denial of Service Vulnerability
Successful exploitation of these vulnerabilities could allow an atta
CISA ICS
OpenSSL Vulnerability
cisa_ics·2014-04-29
OpenSSL Vulnerability
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
OpenSSL Vulnerability
Last RevisedAugust 27, 2018
Alert CodeICSA-14-135-05
## OVERVIEW
This advisory is a follow-up to the updated alert titled ICS-ALERT-14-099-01E Situational Awareness Alert for OpenSSL Vulnerability that was published April 29, 2014, on the NCCIC/ICS-CERT web site.
The OpenSSL (Heartbleed) vulnerability was independently identified by both Neel Mehta of Google Security on April 1, 2014, and 2 days later by a team of security engineers Riku, Antti, and Matti at Codenomicon. https://www.openssl.org/news/secadv_20140407.txt, web site last accessed May 15, 2014.
CISA ICS
Siemens Industrial Products OpenSSL Heartbleed Vulnerability (Update B)
cisa_ics·2014-04-29
Siemens Industrial Products OpenSSL Heartbleed Vulnerability (Update B)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens Industrial Products OpenSSL Heartbleed Vulnerability (Update B)
Last RevisedSeptember 06, 2018
Alert CodeICSA-14-105-03B
## OVERVIEW
This updated advisory is a follow-up to the updated advisory titled ICSA-14-105-03A Siemens Industrial Products OpenSSL Heartbleed Vulnerability that was published April 29, 2014, on the NCCIC/ICS-CERT web site.
Siemens reported to ICS-CERT a list of products affected by the OpenSSL vulnerability (known as “Heartbleed”). Joel Langill of Infrastructure Defense Security Services reported to ICS-CERT and Siemens the OpenSSL vulnerability affe
CISA ICS
Innominate mGuard OpenSSL HeartBleed Vulnerability (Update A)
cisa_ics·2014-04-11
Innominate mGuard OpenSSL HeartBleed Vulnerability (Update A)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Innominate mGuard OpenSSL HeartBleed Vulnerability (Update A)
Last RevisedSeptember 06, 2018
Alert CodeICSA-14-105-02A
## OVERVIEW
Researcher Bob Radvanovsky of Infracritical has notified NCCIC/ICS-CERT that Innominate has released a new firmware version that mitigates the OpenSSL HeartBleed vulnerability in the mGuard products.
## --------- Begin Update A Part 1 of 4 --------
Phoenix Contact branded devices are not likely to be affected, but Phoenix Contact has released a new firmware version to alleviate concern about this vulnerability affecting its products.
## ---------
Cisco
OpenSSL Heartbeat Extension Vulnerability in Multiple Cisco Products
vendor_cisco·2014-04-09·CVSS 5.0
CVE-2014-0160 [MEDIUM] CWE-200 OpenSSL Heartbeat Extension Vulnerability in Multiple Cisco Products
OpenSSL Heartbeat Extension Vulnerability in Multiple Cisco Products
Multiple Cisco products incorporate a version of the OpenSSL package affected by a vulnerability that could allow an unauthenticated, remote attacker to retrieve memory in chunks of 64 kilobytes from a connected client or server.
The vulnerability is due to a missing bounds check in the handling of the Transport Layer Security (TLS) heartbeat extension. An attacker could exploit this vulnerability by implementing a malicious TLS or Datagram Transport Layer Security (DTLS) client, if trying to exploit the vulnerability on an affected server, or a malicious TLS or DTLS server, if trying to exploit the vulnerability on an affected client. An exploit could send a specially crafted TLS or DTLS heartbeat packet to the connect
Cisco
Multiple Vulnerabilities in Cisco ASA Software
vendor_cisco·2014-04-09·CVSS 7.5
CVE-2014-2126 [HIGH] Multiple Vulnerabilities in Cisco ASA Software
Multiple Vulnerabilities in Cisco ASA Software
Cisco Adaptive Security Appliance (ASA) Software is affected by the following vulnerabilities:
Cisco ASA ASDM Privilege Escalation Vulnerability
Cisco ASA SSL VPN Privilege Escalation Vulnerability
Cisco ASA SSL VPN Authentication Bypass Vulnerability
Cisco ASA SIP Denial of Service Vulnerability
These vulnerabilities are independent of one another; a release that is
affected by one of the vulnerabilities may not be affected by the
others.
Successful exploitation of the Cisco ASA ASDM Privilege Escalation Vulnerability and the Cisco ASA SSL VPN Privilege Escalation Vulnerability may allow an attacker or an unprivileged user to elevate privileges and gain administrative access to the affected system.
Successful exploitation of the Cisco AS
Cisco
OpenSSL TLS/DTLS Heartbeat Information Disclosure Vulnerability
vendor_cisco·2014-04-08·CVSS 7.5
CVE-2014-0160 [HIGH] CWE-200 OpenSSL TLS/DTLS Heartbeat Information Disclosure Vulnerability
OpenSSL TLS/DTLS Heartbeat Information Disclosure Vulnerability
A vulnerability in the Transport Layer Security (TLS)/Datagram Transport Layer Security (DTLS) heartbeat functionality in OpenSSL used in multiple Cisco products could allow an unauthenticated, remote attacker to retrieve memory in chunks of 64 kilobytes from a connected client or server.
The vulnerability is due to a missing bounds check in the handling of the TLS heartbeat extension. An attacker could exploit this vulnerability by implementing a malicious TLS or DTLS client, if trying to exploit the vulnerability on an affected server, or a malicious TLS or DTLS server, if trying to exploit the vulnerability on an affected client. The attacker could then send a specially-crafted TLS or DTLS heartbeat packet to the connecte
BSD
FreeBSD-SA-14:06.openssl: OpenSSL multiple vulnerabilities
bsd_advisories·2014-04-08·CVSS 1.9
CVE-2014-0076 [LOW] FreeBSD-SA-14:06.openssl: OpenSSL multiple vulnerabilities
FreeBSD-SA-14:06.openssl Security Advisory
The FreeBSD Project
Topic: OpenSSL multiple vulnerabilities
Category: contrib
Module: openssl
Announced: 2014-04-08
Affects: All supported versions of FreeBSD.
Corrected: 2014-04-08 18:27:39 UTC (stable/10, 10.0-STABLE)
2014-04-08 18:27:46 UTC (releng/10.0, 10.0-RELEASE-p1)
2014-04-08 23:16:19 UTC (stable/9, 9.2-STABLE)
2014-04-08 23:16:05 UTC (releng/9.2, 9.2-RELEASE-p4)
2014-04-08 23:16:05 UTC (releng/9.1, 9.1-RELEASE-p11)
2014-04-08 23:16:19 UTC (stable/8, 8.4-STABLE)
2014-04-08 23:16:05 UTC (releng/8.4, 8.4-RELEASE-p8)
2014-04-08 23:16:05 UTC (releng/8.3, 8.3-RELEASE-p15)
CVE Name: CVE-2014-0076, CVE-2014-0160
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and th
Red Hat
openssl: information disclosure in handling of TLS heartbeat extension packets
vendor_redhat·2014-04-07·CVSS 7.5
CVE-2014-0160 [HIGH] CWE-805 openssl: information disclosure in handling of TLS heartbeat extension packets
openssl: information disclosure in handling of TLS heartbeat extension packets
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.
An information disclosure flaw was found in the way OpenSSL handled TLS and DTLS Heartbeat Extension packets. A malicious TLS or DTLS client or server could send a specially crafted TLS or DTLS Heartbeat packet to disclose a limited portion of memory per request from a connected client or server. Note that the disclosed portions of memory could potentially i
Ubuntu
OpenSSL vulnerabilities
vendor_ubuntu·2014-04-07·CVSS 1.9
CVE-2014-0076 [LOW] OpenSSL vulnerabilities
Title: OpenSSL vulnerabilities
Summary: OpenSSL could be made to expose sensitive information over the network,
possibly including private keys.
Neel Mehta discovered that OpenSSL incorrectly handled memory in the TLS
heartbeat extension. An attacker could use this issue to obtain up to 64k
of memory contents from the client or server, possibly leading to the
disclosure of private keys and other sensitive information. (CVE-2014-0160)
Yuval Yarom and Naomi Benger discovered that OpenSSL incorrectly handled
timing during swap operations in the Montgomery ladder implementation. An
attacker could use this issue to perform side-channel attacks and possibly
recover ECDSA nonces. (CVE-2014-0076)
Instructions: After a standard system update you need to reboot your computer to make all
the nece
Debian
CVE-2014-0160: openssl - The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not p...
vendor_debian·2014·CVSS 7.5
CVE-2014-0160 [HIGH] CVE-2014-0160: openssl - The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not p...
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.
Scope: local
bookworm: resolved (fixed in 1.0.1g-1)
bullseye: resolved (fixed in 1.0.1g-1)
forky: resolved (fixed in 1.0.1g-1)
sid: resolved (fixed in 1.0.1g-1)
trixie: resolved (fixed in 1.0.1g-1)
Cisco
Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
vendor_cisco
CVE-2014-2166 Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
CVE-2014-2166: Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
Cisco TelePresence TC and TE Software are affected by the following vulnerabilities: Six Session Initiation Protocol (SIP) denial of service vulnerabilities Cisco TelePresence TC and TE Software DNS Buffer Overflow Vulnerability Cisco TelePresence TC and TE Software Input Validation Vulnerability Cisco TelePresence TC and TE Software tshell Command Injection Vulnerability Cisco TelePresence TC and TE Software Heap Overflow Vulnerability Cisco TelePresence TC and TE Software U-Boot Buffer Overflow Vulnerability Cisco TelePresence TC and TE Software Unauthenticated Serial Port Access Vulnerability Cisco TelePresence TC H.225 Denial of Service Vulnerability Successful exploitation of these vulnerabilities could a
Cisco
Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
vendor_cisco
CVE-2014-2169 Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
CVE-2014-2169: Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
Cisco TelePresence TC and TE Software are affected by the following vulnerabilities: Six Session Initiation Protocol (SIP) denial of service vulnerabilities Cisco TelePresence TC and TE Software DNS Buffer Overflow Vulnerability Cisco TelePresence TC and TE Software Input Validation Vulnerability Cisco TelePresence TC and TE Software tshell Command Injection Vulnerability Cisco TelePresence TC and TE Software Heap Overflow Vulnerability Cisco TelePresence TC and TE Software U-Boot Buffer Overflow Vulnerability Cisco TelePresence TC and TE Software Unauthenticated Serial Port Access Vulnerability Cisco TelePresence TC H.225 Denial of Service Vulnerability Successful exploitation of these vulnerabilities could a
Cisco
Multiple Vulnerabilities in Cisco TelePresence System MXP Series
vendor_cisco
CVE-2014-2161 Multiple Vulnerabilities in Cisco TelePresence System MXP Series
CVE-2014-2161: Multiple Vulnerabilities in Cisco TelePresence System MXP Series
Cisco TelePresence System MXP Series Software contains the following vulnerabilities: Three SIP denial of service vulnerabilities Three H.225 denial of service vulnerabilities Successful exploitation of these vulnerabilities may allow an attacker to cause system instability and the affected system to reload. Note: This security advisory does not provide information about the OpenSSL TLS Heartbeat Read Overrun Vulnerability identified by CVE-2014-0160 (also known as Heartbleed). For additional information regarding Cisco products affected by the Heartbleed vulnerability, refer to the Cisco Security Advisory available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvi
Cisco
Multiple Vulnerabilities in Cisco TelePresence System MXP Series
vendor_cisco
CVE-2014-2157 Multiple Vulnerabilities in Cisco TelePresence System MXP Series
CVE-2014-2157: Multiple Vulnerabilities in Cisco TelePresence System MXP Series
Cisco TelePresence System MXP Series Software contains the following vulnerabilities: Three SIP denial of service vulnerabilities Three H.225 denial of service vulnerabilities Successful exploitation of these vulnerabilities may allow an attacker to cause system instability and the affected system to reload. Note: This security advisory does not provide information about the OpenSSL TLS Heartbeat Read Overrun Vulnerability identified by CVE-2014-0160 (also known as Heartbleed). For additional information regarding Cisco products affected by the Heartbleed vulnerability, refer to the Cisco Security Advisory available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvi
Cisco
Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
vendor_cisco
CVE-2014-2173 Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
CVE-2014-2173: Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
Cisco TelePresence TC and TE Software are affected by the following vulnerabilities: Six Session Initiation Protocol (SIP) denial of service vulnerabilities Cisco TelePresence TC and TE Software DNS Buffer Overflow Vulnerability Cisco TelePresence TC and TE Software Input Validation Vulnerability Cisco TelePresence TC and TE Software tshell Command Injection Vulnerability Cisco TelePresence TC and TE Software Heap Overflow Vulnerability Cisco TelePresence TC and TE Software U-Boot Buffer Overflow Vulnerability Cisco TelePresence TC and TE Software Unauthenticated Serial Port Access Vulnerability Cisco TelePresence TC H.225 Denial of Service Vulnerability Successful exploitation of these vulnerabilities could a
Cisco
Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
vendor_cisco
CVE-2014-2163 Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
CVE-2014-2163: Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
Cisco TelePresence TC and TE Software are affected by the following vulnerabilities: Six Session Initiation Protocol (SIP) denial of service vulnerabilities Cisco TelePresence TC and TE Software DNS Buffer Overflow Vulnerability Cisco TelePresence TC and TE Software Input Validation Vulnerability Cisco TelePresence TC and TE Software tshell Command Injection Vulnerability Cisco TelePresence TC and TE Software Heap Overflow Vulnerability Cisco TelePresence TC and TE Software U-Boot Buffer Overflow Vulnerability Cisco TelePresence TC and TE Software Unauthenticated Serial Port Access Vulnerability Cisco TelePresence TC H.225 Denial of Service Vulnerability Successful exploitation of these vulnerabilities could a
Cisco
Multiple Vulnerabilities in Cisco TelePresence System MXP Series
vendor_cisco
CVE-2014-2159 Multiple Vulnerabilities in Cisco TelePresence System MXP Series
CVE-2014-2159: Multiple Vulnerabilities in Cisco TelePresence System MXP Series
Cisco TelePresence System MXP Series Software contains the following vulnerabilities: Three SIP denial of service vulnerabilities Three H.225 denial of service vulnerabilities Successful exploitation of these vulnerabilities may allow an attacker to cause system instability and the affected system to reload. Note: This security advisory does not provide information about the OpenSSL TLS Heartbeat Read Overrun Vulnerability identified by CVE-2014-0160 (also known as Heartbleed). For additional information regarding Cisco products affected by the Heartbleed vulnerability, refer to the Cisco Security Advisory available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvi
Cisco
Multiple Vulnerabilities in Cisco TelePresence System MXP Series
vendor_cisco
CVE-2014-2160 Multiple Vulnerabilities in Cisco TelePresence System MXP Series
CVE-2014-2160: Multiple Vulnerabilities in Cisco TelePresence System MXP Series
Cisco TelePresence System MXP Series Software contains the following vulnerabilities: Three SIP denial of service vulnerabilities Three H.225 denial of service vulnerabilities Successful exploitation of these vulnerabilities may allow an attacker to cause system instability and the affected system to reload. Note: This security advisory does not provide information about the OpenSSL TLS Heartbeat Read Overrun Vulnerability identified by CVE-2014-0160 (also known as Heartbleed). For additional information regarding Cisco products affected by the Heartbleed vulnerability, refer to the Cisco Security Advisory available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvi
Cisco
Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
vendor_cisco
CVE-2014-2165 Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
CVE-2014-2165: Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
Cisco TelePresence TC and TE Software are affected by the following vulnerabilities: Six Session Initiation Protocol (SIP) denial of service vulnerabilities Cisco TelePresence TC and TE Software DNS Buffer Overflow Vulnerability Cisco TelePresence TC and TE Software Input Validation Vulnerability Cisco TelePresence TC and TE Software tshell Command Injection Vulnerability Cisco TelePresence TC and TE Software Heap Overflow Vulnerability Cisco TelePresence TC and TE Software U-Boot Buffer Overflow Vulnerability Cisco TelePresence TC and TE Software Unauthenticated Serial Port Access Vulnerability Cisco TelePresence TC H.225 Denial of Service Vulnerability Successful exploitation of these vulnerabilities could a
Cisco
Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
vendor_cisco
CVE-2014-2172 Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
CVE-2014-2172: Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
Cisco TelePresence TC and TE Software are affected by the following vulnerabilities: Six Session Initiation Protocol (SIP) denial of service vulnerabilities Cisco TelePresence TC and TE Software DNS Buffer Overflow Vulnerability Cisco TelePresence TC and TE Software Input Validation Vulnerability Cisco TelePresence TC and TE Software tshell Command Injection Vulnerability Cisco TelePresence TC and TE Software Heap Overflow Vulnerability Cisco TelePresence TC and TE Software U-Boot Buffer Overflow Vulnerability Cisco TelePresence TC and TE Software Unauthenticated Serial Port Access Vulnerability Cisco TelePresence TC H.225 Denial of Service Vulnerability Successful exploitation of these vulnerabilities could a
Apache
Apache tomcat: CVE-2014-0160
vendor_apache·CVSS 7.5
CVE-2014-0160 [HIGH] Apache tomcat: CVE-2014-0160
Apache tomcat: CVE-2014-0160
(a.k.a. "Heartbleed") A bug in certain versions of OpenSSL can allow an unauthenticated remote user to read certain contents of the server's memory. Binary versions of tcnative 1.1.24 - 1.1.29 include this vulnerable version of OpenSSL. tcnative 1.1.30 and later ship with patched versions of OpenSSL. This issue was first announced on 7 April 2014. Affects: OpenSSL 1.0.1-1.0.1f, tcnative 1.1.24-1.1.29 Not a vulnerability in Tomcat Critical: Remote Code Execution via log4j
Cisco
Multiple Vulnerabilities in Cisco TelePresence System MXP Series
vendor_cisco
CVE-2014-2156 Multiple Vulnerabilities in Cisco TelePresence System MXP Series
CVE-2014-2156: Multiple Vulnerabilities in Cisco TelePresence System MXP Series
Cisco TelePresence System MXP Series Software contains the following vulnerabilities: Three SIP denial of service vulnerabilities Three H.225 denial of service vulnerabilities Successful exploitation of these vulnerabilities may allow an attacker to cause system instability and the affected system to reload. Note: This security advisory does not provide information about the OpenSSL TLS Heartbeat Read Overrun Vulnerability identified by CVE-2014-0160 (also known as Heartbleed). For additional information regarding Cisco products affected by the Heartbleed vulnerability, refer to the Cisco Security Advisory available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvi
Cisco
Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
vendor_cisco
CVE-2014-2162 Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
CVE-2014-2162: Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
Cisco TelePresence TC and TE Software are affected by the following vulnerabilities: Six Session Initiation Protocol (SIP) denial of service vulnerabilities Cisco TelePresence TC and TE Software DNS Buffer Overflow Vulnerability Cisco TelePresence TC and TE Software Input Validation Vulnerability Cisco TelePresence TC and TE Software tshell Command Injection Vulnerability Cisco TelePresence TC and TE Software Heap Overflow Vulnerability Cisco TelePresence TC and TE Software U-Boot Buffer Overflow Vulnerability Cisco TelePresence TC and TE Software Unauthenticated Serial Port Access Vulnerability Cisco TelePresence TC H.225 Denial of Service Vulnerability Successful exploitation of these vulnerabilities could a
Cisco
Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
vendor_cisco
CVE-2014-2164 Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
CVE-2014-2164: Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
Cisco TelePresence TC and TE Software are affected by the following vulnerabilities: Six Session Initiation Protocol (SIP) denial of service vulnerabilities Cisco TelePresence TC and TE Software DNS Buffer Overflow Vulnerability Cisco TelePresence TC and TE Software Input Validation Vulnerability Cisco TelePresence TC and TE Software tshell Command Injection Vulnerability Cisco TelePresence TC and TE Software Heap Overflow Vulnerability Cisco TelePresence TC and TE Software U-Boot Buffer Overflow Vulnerability Cisco TelePresence TC and TE Software Unauthenticated Serial Port Access Vulnerability Cisco TelePresence TC H.225 Denial of Service Vulnerability Successful exploitation of these vulnerabilities could a
Cisco
Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
vendor_cisco
CVE-2014-2168 Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
CVE-2014-2168: Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
Cisco TelePresence TC and TE Software are affected by the following vulnerabilities: Six Session Initiation Protocol (SIP) denial of service vulnerabilities Cisco TelePresence TC and TE Software DNS Buffer Overflow Vulnerability Cisco TelePresence TC and TE Software Input Validation Vulnerability Cisco TelePresence TC and TE Software tshell Command Injection Vulnerability Cisco TelePresence TC and TE Software Heap Overflow Vulnerability Cisco TelePresence TC and TE Software U-Boot Buffer Overflow Vulnerability Cisco TelePresence TC and TE Software Unauthenticated Serial Port Access Vulnerability Cisco TelePresence TC H.225 Denial of Service Vulnerability Successful exploitation of these vulnerabilities could a
Cisco
Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
vendor_cisco
CVE-2014-2171 Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
CVE-2014-2171: Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
Cisco TelePresence TC and TE Software are affected by the following vulnerabilities: Six Session Initiation Protocol (SIP) denial of service vulnerabilities Cisco TelePresence TC and TE Software DNS Buffer Overflow Vulnerability Cisco TelePresence TC and TE Software Input Validation Vulnerability Cisco TelePresence TC and TE Software tshell Command Injection Vulnerability Cisco TelePresence TC and TE Software Heap Overflow Vulnerability Cisco TelePresence TC and TE Software U-Boot Buffer Overflow Vulnerability Cisco TelePresence TC and TE Software Unauthenticated Serial Port Access Vulnerability Cisco TelePresence TC H.225 Denial of Service Vulnerability Successful exploitation of these vulnerabilities could a
Cisco
Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
vendor_cisco
CVE-2014-2170 Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
CVE-2014-2170: Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
Cisco TelePresence TC and TE Software are affected by the following vulnerabilities: Six Session Initiation Protocol (SIP) denial of service vulnerabilities Cisco TelePresence TC and TE Software DNS Buffer Overflow Vulnerability Cisco TelePresence TC and TE Software Input Validation Vulnerability Cisco TelePresence TC and TE Software tshell Command Injection Vulnerability Cisco TelePresence TC and TE Software Heap Overflow Vulnerability Cisco TelePresence TC and TE Software U-Boot Buffer Overflow Vulnerability Cisco TelePresence TC and TE Software Unauthenticated Serial Port Access Vulnerability Cisco TelePresence TC H.225 Denial of Service Vulnerability Successful exploitation of these vulnerabilities could a
Cisco
Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
vendor_cisco
CVE-2014-2175 Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
CVE-2014-2175: Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
Cisco TelePresence TC and TE Software are affected by the following vulnerabilities: Six Session Initiation Protocol (SIP) denial of service vulnerabilities Cisco TelePresence TC and TE Software DNS Buffer Overflow Vulnerability Cisco TelePresence TC and TE Software Input Validation Vulnerability Cisco TelePresence TC and TE Software tshell Command Injection Vulnerability Cisco TelePresence TC and TE Software Heap Overflow Vulnerability Cisco TelePresence TC and TE Software U-Boot Buffer Overflow Vulnerability Cisco TelePresence TC and TE Software Unauthenticated Serial Port Access Vulnerability Cisco TelePresence TC H.225 Denial of Service Vulnerability Successful exploitation of these vulnerabilities could a
Cisco
Multiple Vulnerabilities in Cisco TelePresence System MXP Series
vendor_cisco
CVE-2014-2158 Multiple Vulnerabilities in Cisco TelePresence System MXP Series
CVE-2014-2158: Multiple Vulnerabilities in Cisco TelePresence System MXP Series
Cisco TelePresence System MXP Series Software contains the following vulnerabilities: Three SIP denial of service vulnerabilities Three H.225 denial of service vulnerabilities Successful exploitation of these vulnerabilities may allow an attacker to cause system instability and the affected system to reload. Note: This security advisory does not provide information about the OpenSSL TLS Heartbeat Read Overrun Vulnerability identified by CVE-2014-0160 (also known as Heartbleed). For additional information regarding Cisco products affected by the Heartbleed vulnerability, refer to the Cisco Security Advisory available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvi
Cisco
Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
vendor_cisco
CVE-2014-2167 Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
CVE-2014-2167: Multiple Vulnerabilities in Cisco TelePresence TC and TE Software
Cisco TelePresence TC and TE Software are affected by the following vulnerabilities: Six Session Initiation Protocol (SIP) denial of service vulnerabilities Cisco TelePresence TC and TE Software DNS Buffer Overflow Vulnerability Cisco TelePresence TC and TE Software Input Validation Vulnerability Cisco TelePresence TC and TE Software tshell Command Injection Vulnerability Cisco TelePresence TC and TE Software Heap Overflow Vulnerability Cisco TelePresence TC and TE Software U-Boot Buffer Overflow Vulnerability Cisco TelePresence TC and TE Software Unauthenticated Serial Port Access Vulnerability Cisco TelePresence TC H.225 Denial of Service Vulnerability Successful exploitation of these vulnerabilities could a
Cisco
Multiple Vulnerabilities in Cisco ASA Software
vendor_cisco
CVE-2014-0160 Multiple Vulnerabilities in Cisco ASA Software
CVE-2014-0160: Multiple Vulnerabilities in Cisco ASA Software
Cisco Adaptive Security Appliance (ASA) Software is affected by the following vulnerabilities: Cisco ASA ASDM Privilege Escalation Vulnerability Cisco ASA SSL VPN Privilege Escalation Vulnerability Cisco ASA SSL VPN Authentication Bypass Vulnerability Cisco ASA SIP Denial of Service Vulnerability These vulnerabilities are independent of one another; a release that is affected by one of the vulnerabilities may not be affected by the others. Successful exploitation of the Cisco ASA ASDM Privilege Escalation Vulnerability and the Cisco ASA SSL VPN Privilege Escalation Vulnerability may allow an attacker or an unprivileged user to elevate privileges and gain administrative access to the affected system. Successful exploitation of th
GHSA
GHSA-5vg7-rfpp-g2rq: IBM WebSphere Application Server (WAS) 6
ghsa_unreviewed·2022-05-17·CVSS 7.5
CVE-2014-0964 [HIGH] GHSA-5vg7-rfpp-g2rq: IBM WebSphere Application Server (WAS) 6
IBM WebSphere Application Server (WAS) 6.1.0.0 through 6.1.0.47 and 6.0.2.0 through 6.0.2.43 allows remote attackers to cause a denial of service via crafted TLS traffic, as demonstrated by traffic from a CVE-2014-0160 vulnerability-assessment tool.
GHSA
GHSA-mq67-6m35-r8cm: The server in HP Integrated Lights-Out 2 (aka iLO 2) 2
ghsa_unreviewed·2022-05-17·CVSS 7.5
CVE-2014-2601 [HIGH] GHSA-mq67-6m35-r8cm: The server in HP Integrated Lights-Out 2 (aka iLO 2) 2
The server in HP Integrated Lights-Out 2 (aka iLO 2) 2.23 and earlier allows remote attackers to cause a denial of service via crafted HTTPS traffic, as demonstrated by traffic from a CVE-2014-0160 vulnerability-assessment tool.
GHSA
GHSA-w8r8-w5w4-4w4v: The (1) TLS and (2) DTLS implementations in OpenSSL 1
ghsa_unreviewed·2022-05-13
CVE-2014-0160 [HIGH] CWE-119 GHSA-w8r8-w5w4-4w4v: The (1) TLS and (2) DTLS implementations in OpenSSL 1
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.
OSV
CVE-2014-0160: The (1) TLS and (2) DTLS implementations in OpenSSL 1
osv·2014-04-07·CVSS 7.5
CVE-2014-0160 [HIGH] CVE-2014-0160: The (1) TLS and (2) DTLS implementations in OpenSSL 1
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.
VulnCheck
OpenSSL Information Disclosure Vulnerability
vulncheck·2014·CVSS 7.5
CVE-2014-0160 [HIGH] CWE-125 OpenSSL Information Disclosure Vulnerability
OpenSSL Information Disclosure Vulnerability
The TLS and DTLS implementations in OpenSSL do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information.
Affected: OpenSSL OpenSSL
Required Action: Apply updates per vendor instructions.
Exploitation References: https://cisa.gov/news-events/alerts/2015/04/29/top-30-targeted-high-risk-vulnerabilities; https://www.us-cert.gov/ncas/alerts/TA15-119A; https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/leafminer-espionage-middle-east; https://www.ic3.gov/Media/News/2022/220126.pdf; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.csoonline.com/article/2096402/most-attacks-affecting-smbs-target-five-older-vulnerabilities.html;
Suricata
ET EXPLOIT Possible TLS HeartBleed Unencrypted Request Method 4 (Inbound to Common SSL Port)
suricata·2014-04-15
CVE-2014-0160 ET EXPLOIT Possible TLS HeartBleed Unencrypted Request Method 4 (Inbound to Common SSL Port)
ET EXPLOIT Possible TLS HeartBleed Unencrypted Request Method 4 (Inbound to Common SSL Port)
Rule: alert tcp any any -> $HOME_NET [443,636,989,990,992,993,994,995,5061,25] (msg:"ET EXPLOIT Possible TLS HeartBleed Unencrypted Request Method 4 (Inbound to Common SSL Port)"; flow:established,to_server; content:"|18 03|"; byte_test:1,,150,0,relative; isdataat:!18,relative; threshold:type limit,track by_src,count 1,seconds 120; reference:cve,2014-0160; reference:url,blog.inliniac.net/2014/04/08/detecting-openssl-heartbleed-with-suricata/; reference:url,heartbleed.com/; reference:url,blog.fox-it.com/2014/04/08/openssl-heartbleed-bug-live-blog/; classtype:bad-unknown; sid:2018388; rev:3; metadata:created_at 2014_04_15, cve CVE_2014_0160, confidence Medium, signature_severity Major, tag Descripti
Suricata
ET EXPLOIT Possible TLS HeartBleed Unencrypted Request Method 3 (Inbound to Common SSL Port)
suricata·2014-04-15
CVE-2014-0160 ET EXPLOIT Possible TLS HeartBleed Unencrypted Request Method 3 (Inbound to Common SSL Port)
ET EXPLOIT Possible TLS HeartBleed Unencrypted Request Method 3 (Inbound to Common SSL Port)
Rule: alert tcp any any -> $HOME_NET [443,636,989,990,992,993,994,995,5061,25] (msg:"ET EXPLOIT Possible TLS HeartBleed Unencrypted Request Method 3 (Inbound to Common SSL Port)"; flow:established,to_server; content:"|18 03|"; depth:2; byte_test:1,,150,0,relative; byte_test:2,>,rec_len,0,relative; threshold:type limit,track by_src,count 1,seconds 120; reference:cve,2014-0160; reference:url,blog.inliniac.net/2014/04/08/detecting-openssl-heartbleed-with-suricata/; reference:url,heartbleed.com/; reference:url,blog.fox-it.com/2014/04/08/openssl-heartbleed-bug-live-blog/; classtype:bad-unknown; sid:2018389; rev:4; metadata:created_at 2014_04_15, cve CVE_2014_0160, confidence Medium, signature_severity
Suricata
ET EXPLOIT Possible OpenSSL HeartBleed Large HeartBeat Response from Common SSL Port (Outbound from Server)
suricata·2014-04-11
CVE-2014-0160 ET EXPLOIT Possible OpenSSL HeartBleed Large HeartBeat Response from Common SSL Port (Outbound from Server)
ET EXPLOIT Possible OpenSSL HeartBleed Large HeartBeat Response from Common SSL Port (Outbound from Server)
Rule: alert tcp $HOME_NET [21,25,110,143,443,465,587,636,989:995,5061,5222] -> $EXTERNAL_NET any (msg:"ET EXPLOIT Possible OpenSSL HeartBleed Large HeartBeat Response from Common SSL Port (Outbound from Server)"; flow:established,to_client; content:"|18 03|"; depth:2; byte_test:1,,150,3; byte_test:2,<,17000,3; threshold:type limit,track by_dst,count 1,seconds 120; reference:cve,2014-0160; reference:url,blog.inliniac.net/2014/04/08/detecting-openssl-heartbleed-with-suricata/; reference:url,heartbleed.com/; reference:url,blog.fox-it.com/2014/04/08/openssl-heartbleed-bug-live-blog/; classtype:bad-unknown; sid:2018382; rev:9; metadata:created_at 2014_04_11, cve CVE_2014_0160, confidence
Suricata
ET EXPLOIT Possible OpenSSL HeartBleed Large HeartBeat Response from Common SSL Port (Outbound from Client)
suricata·2014-04-11
CVE-2014-0160 ET EXPLOIT Possible OpenSSL HeartBleed Large HeartBeat Response from Common SSL Port (Outbound from Client)
ET EXPLOIT Possible OpenSSL HeartBleed Large HeartBeat Response from Common SSL Port (Outbound from Client)
Rule: alert tcp $HOME_NET any -> $EXTERNAL_NET [21,25,110,143,443,465,587,636,989:995,5061,5222] (msg:"ET EXPLOIT Possible OpenSSL HeartBleed Large HeartBeat Response from Common SSL Port (Outbound from Client)"; flow:established,to_server; content:"|18 03|"; depth:2; byte_test:1,,150,3; byte_test:2,<,17000,3; threshold:type limit,track by_src,count 1,seconds 120; reference:cve,2014-0160; reference:url,blog.inliniac.net/2014/04/08/detecting-openssl-heartbleed-with-suricata/; reference:url,heartbleed.com/; reference:url,blog.fox-it.com/2014/04/08/openssl-heartbleed-bug-live-blog/; classtype:bad-unknown; sid:2018383; rev:10; metadata:created_at 2014_04_11, cve CVE_2014_0160, confidenc
Suricata
ET EXPLOIT TLS HeartBeat Request (Client Initiated) fb set
suricata·2014-04-09
CVE-2014-0160 ET EXPLOIT TLS HeartBeat Request (Client Initiated) fb set
ET EXPLOIT TLS HeartBeat Request (Client Initiated) fb set
Rule: alert tcp any any -> $HOME_NET any (msg:"ET EXPLOIT TLS HeartBeat Request (Client Initiated) fb set"; flow:established,to_server; flowbits:isnotset,ET.HB.Response.CI; flowbits:set,ET.HB.Request.CI; flowbits:noalert; content:"|18 03|"; depth:2; byte_test:1,<,4,2; reference:cve,2014-0160; reference:url,blog.inliniac.net/2014/04/08/detecting-openssl-heartbleed-with-suricata/; reference:url,heartbleed.com/; reference:url,blog.fox-it.com/2014/04/08/openssl-heartbleed-bug-live-blog/; classtype:bad-unknown; sid:2018376; rev:6; metadata:created_at 2014_04_09, cve CVE_2014_0160, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_14;)
Suricata
ET EXPLOIT TLS HeartBeat Request (Server Initiated) fb set
suricata·2014-04-09
CVE-2014-0160 ET EXPLOIT TLS HeartBeat Request (Server Initiated) fb set
ET EXPLOIT TLS HeartBeat Request (Server Initiated) fb set
Rule: alert tcp any any -> $HOME_NET any (msg:"ET EXPLOIT TLS HeartBeat Request (Server Initiated) fb set"; flow:established,to_client; flowbits:isnotset,ET.HB.Response.SI; flowbits:set,ET.HB.Request.SI; flowbits:noalert; content:"|18 03|"; depth:2; byte_test:1,<,4,2; reference:cve,2014-0160; reference:url,blog.inliniac.net/2014/04/08/detecting-openssl-heartbleed-with-suricata/; reference:url,heartbleed.com/; reference:url,blog.fox-it.com/2014/04/08/openssl-heartbleed-bug-live-blog/; classtype:bad-unknown; sid:2018375; rev:6; metadata:created_at 2014_04_09, cve CVE_2014_0160, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_14;)
Suricata
ET EXPLOIT Possible OpenSSL HeartBleed Large HeartBeat Response (Server Init Vuln Client)
suricata·2014-04-09
CVE-2014-0160 ET EXPLOIT Possible OpenSSL HeartBleed Large HeartBeat Response (Server Init Vuln Client)
ET EXPLOIT Possible OpenSSL HeartBleed Large HeartBeat Response (Server Init Vuln Client)
Rule: alert tcp $HOME_NET any -> any any (msg:"ET EXPLOIT Possible OpenSSL HeartBleed Large HeartBeat Response (Server Init Vuln Client)"; flow:established,to_server; flowbits:isnotset,ET.HB.Response.SI; flowbits:isset,ET.HB.Request.SI; flowbits:set,ET.HB.Response.SI; flowbits:unset,ET.HB.Request.SI; content:"|18 03|"; depth:2; byte_test:1,,150,3; threshold:type limit,track by_src,count 1,seconds 120; reference:cve,2014-0160; reference:url,blog.inliniac.net/2014/04/08/detecting-openssl-heartbleed-with-suricata/; reference:url,heartbleed.com/; reference:url,blog.fox-it.com/2014/04/08/openssl-heartbleed-bug-live-blog/; classtype:bad-unknown; sid:2018378; rev:7; metadata:created_at 2014_04_09, cve CVE_2
Suricata
ET EXPLOIT Possible OpenSSL HeartBleed Large HeartBeat Response (Client Init Vuln Server)
suricata·2014-04-09
CVE-2014-0160 ET EXPLOIT Possible OpenSSL HeartBleed Large HeartBeat Response (Client Init Vuln Server)
ET EXPLOIT Possible OpenSSL HeartBleed Large HeartBeat Response (Client Init Vuln Server)
Rule: alert tcp $HOME_NET any -> any any (msg:"ET EXPLOIT Possible OpenSSL HeartBleed Large HeartBeat Response (Client Init Vuln Server)"; flow:established,to_client; flowbits:isnotset,ET.HB.Response.CI; flowbits:isset,ET.HB.Request.CI; flowbits:set,ET.HB.Response.CI; flowbits:unset,ET.HB.Request.CI; content:"|18 03|"; depth:2; byte_test:1,,150,3; threshold:type limit,track by_src,count 1,seconds 120; reference:cve,2014-0160; reference:url,blog.inliniac.net/2014/04/08/detecting-openssl-heartbleed-with-suricata/; reference:url,heartbleed.com/; reference:url,blog.fox-it.com/2014/04/08/openssl-heartbleed-bug-live-blog/; classtype:bad-unknown; sid:2018377; rev:5; metadata:created_at 2014_04_09, cve CVE_2
Suricata
ET RETIRED Malformed HeartBeat Response
suricata·2014-04-08
CVE-2014-0160 ET RETIRED Malformed HeartBeat Response
ET RETIRED Malformed HeartBeat Response
Rule: alert tcp $HOME_NET [!$HTTP_PORTS,!445,!22] -> any any (msg:"ET RETIRED Malformed HeartBeat Response"; flow:established,to_client; flowbits:isset,ET.MalformedTLSHB; content:"|18 03|"; depth:2; byte_test:1,,200,3; threshold:type limit,track by_src,count 1,seconds 120; reference:cve,2014-0160; reference:url,blog.inliniac.net/2014/04/08/detecting-openssl-heartbleed-with-suricata/; reference:url,heartbleed.com/; reference:url,blog.fox-it.com/2014/04/08/openssl-heartbleed-bug-live-blog/; classtype:bad-unknown; sid:2018373; rev:7; metadata:created_at 2014_04_08, cve CVE_2014_0160, former_category EXPLOIT, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2025_04_17;)
Suricata
ET RETIRED Malformed HeartBeat Request
suricata·2014-04-08
CVE-2014-0160 ET RETIRED Malformed HeartBeat Request
ET RETIRED Malformed HeartBeat Request
Rule: alert tcp any any -> $HOME_NET !$HTTP_PORTS (msg:"ET RETIRED Malformed HeartBeat Request"; flow:established,to_server; flowbits:set,ET.MalformedTLSHB; content:"|18 03|"; depth:2; byte_test:1,,2,3; byte_test:2,>,record_len,6; threshold:type limit,track by_src,count 1,seconds 120; reference:cve,2014-0160; reference:url,blog.inliniac.net/2014/04/08/detecting-openssl-heartbleed-with-suricata/; reference:url,heartbleed.com/; reference:url,blog.fox-it.com/2014/04/08/openssl-heartbleed-bug-live-blog/; classtype:bad-unknown; sid:2018372; rev:5; metadata:created_at 2014_04_08, cve CVE_2014_0160, former_category EXPLOIT, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2025_04_17;)
Suricata
ET RETIRED Malformed HeartBeat Request method 2
suricata·2014-04-08
CVE-2014-0160 ET RETIRED Malformed HeartBeat Request method 2
ET RETIRED Malformed HeartBeat Request method 2
Rule: alert tcp any any -> $HOME_NET !$HTTP_PORTS (msg:"ET RETIRED Malformed HeartBeat Request method 2"; flow:established,to_server; flowbits:set,ET.MalformedTLSHB; flowbits:noalert; content:"|18 03|"; depth:2; byte_test:1,,2,3; byte_test:2,>,200,6; threshold:type limit,track by_src,count 1,seconds 120; reference:cve,2014-0160; reference:url,blog.inliniac.net/2014/04/08/detecting-openssl-heartbleed-with-suricata/; reference:url,heartbleed.com/; reference:url,blog.fox-it.com/2014/04/08/openssl-heartbleed-bug-live-blog/; classtype:bad-unknown; sid:2018374; rev:5; metadata:created_at 2014_04_08, cve CVE_2014_0160, former_category EXPLOIT, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2025_04_17;)
Exploit-DB
OpenSSL TLS Heartbeat Extension - 'Heartbleed' Information Leak (2) (DTLS Support)
exploitdb·2014-04-24·CVSS 7.5
CVE-2014-0346 [HIGH] OpenSSL TLS Heartbeat Extension - 'Heartbleed' Information Leak (2) (DTLS Support)
OpenSSL TLS Heartbeat Extension - 'Heartbleed' Information Leak (2) (DTLS Support)
---
/*
* CVE-2014-0160 heartbleed OpenSSL information leak exploit
* =========================================================
* This exploit uses OpenSSL to create an encrypted connection
* and trigger the heartbleed leak. The leaked information is
* returned within encrypted SSL packets and is then decrypted
* and wrote to a file to annoy IDS/forensics. The exploit can
* set heartbeat payload length arbitrarily or use two preset
* values for NULL and MAX length. The vulnerability occurs due
* to bounds checking not being performed on a heap value which
* is user supplied and returned to the user as part of DTLS/TLS
* heartbeat SSL extension. All versions of OpenSSL 1.0.1 to
* 1.0.1f are known affected. Y
Exploit-DB
OpenSSL TLS Heartbeat Extension - 'Heartbleed' Information Leak (1)
exploitdb·2014-04-10·CVSS 7.5
CVE-2014-0346 [HIGH] OpenSSL TLS Heartbeat Extension - 'Heartbleed' Information Leak (1)
OpenSSL TLS Heartbeat Extension - 'Heartbleed' Information Leak (1)
---
/*
* CVE-2014-0160 heartbleed OpenSSL information leak exploit
* =========================================================
* This exploit uses OpenSSL to create an encrypted connection
* and trigger the heartbleed leak. The leaked information is
* returned within encrypted SSL packets and is then decrypted
* and wrote to a file to annoy IDS/forensics. The exploit can
* set heartbeat payload length arbitrarily or use two preset
* values for NULL and MAX length. The vulnerability occurs due
* to bounds checking not being performed on a heap value which
* is user supplied and returned to the user as part of DTLS/TLS
* heartbeat SSL extension. All versions of OpenSSL 1.0.1 to
* 1.0.1f are known affected. You must run thi
Exploit-DB
OpenSSL 1.0.1f TLS Heartbeat Extension - 'Heartbleed' Memory Disclosure (Multiple SSL/TLS Versions)
exploitdb·2014-04-09·CVSS 7.5
CVE-2014-0346 [HIGH] OpenSSL 1.0.1f TLS Heartbeat Extension - 'Heartbleed' Memory Disclosure (Multiple SSL/TLS Versions)
OpenSSL 1.0.1f TLS Heartbeat Extension - 'Heartbleed' Memory Disclosure (Multiple SSL/TLS Versions)
---
# Exploit Title: [OpenSSL TLS Heartbeat Extension - Memory Disclosure - Multiple SSL/TLS versions]
# Date: [2014-04-09]
# Exploit Author: [Csaba Fitzl]
# Vendor Homepage: [http://www.openssl.org/]
# Software Link: [http://www.openssl.org/source/openssl-1.0.1f.tar.gz]
# Version: [1.0.1f]
# Tested on: [N/A]
# CVE : [2014-0160]
#!/usr/bin/env python
# Quick and dirty demonstration of CVE-2014-0160 by Jared Stafford ([email protected])
# The author disclaims copyright to this source code.
# Modified by Csaba Fitzl for multiple SSL / TLS version support
import sys
import struct
import socket
import time
import select
import re
from optparse import OptionParser
options = OptionPar
Exploit-DB
OpenSSL TLS Heartbeat Extension - 'Heartbleed' Memory Disclosure
exploitdb·2014-04-08·CVSS 7.5
CVE-2014-0346 [HIGH] OpenSSL TLS Heartbeat Extension - 'Heartbleed' Memory Disclosure
OpenSSL TLS Heartbeat Extension - 'Heartbleed' Memory Disclosure
---
#!/usr/bin/python
# Quick and dirty demonstration of CVE-2014-0160 by Jared Stafford ([email protected])
# The author disclaims copyright to this source code.
import sys
import struct
import socket
import time
import select
import re
from optparse import OptionParser
options = OptionParser(usage='%prog server [options]', description='Test for SSL heartbeat vulnerability (CVE-2014-0160)')
options.add_option('-p', '--port', type='int', default=443, help='TCP port to test (default: 443)')
def h2bin(x):
return x.replace(' ', '').replace('\n', '').decode('hex')
hello = h2bin('''
16 03 02 00 dc 01 00 00 d8 03 02 53
43 5b 90 9d 9b 72 0b bc 0c bc 2b 92 a8 48 97 cf
bd 39 04 cc 16 0a 85 03 90 9f 77 04 33 d4 de 00
00 66
Metasploit
OpenSSL Heartbeat (Heartbleed) Information Leak
metasploit
OpenSSL Heartbeat (Heartbleed) Information Leak
OpenSSL Heartbeat (Heartbleed) Information Leak
This module implements the OpenSSL Heartbleed attack. The problem exists in the handling of heartbeat requests, where a fake length can be used to leak memory data in the response. Services that support STARTTLS may also be vulnerable. The module supports several actions, allowing for scanning, dumping of memory contents to loot, and private key recovery. The LEAK_COUNT option can be used to specify leaks per SCAN or DUMP. The repeat command can be used to make running the SCAN or DUMP many times more powerful. As in: repeat -t 60 run; sleep 2 To run every two seconds for one minute.
Nuclei
OpenSSL Heartbleed Vulnerability
nuclei·CVSS 7.5
CVE-2014-0160 [HIGH] OpenSSL Heartbleed Vulnerability
OpenSSL Heartbleed Vulnerability
The Heartbleed bug allows anyone on the Internet to read the memory of the systems protected by the vulnerable versions of the OpenSSL software. This compromises the secret keys used to identify the service providers and to encrypt the traffic, the names and passwords of the users, and the actual content. This allows attackers to eavesdrop on communications, steal data directly from the services and users, and impersonate services and users.
Template:
id: CVE-2014-0160
info:
name: OpenSSL Heartbleed Vulnerability
author: pussycat0x
severity: high
description: |
The Heartbleed bug allows anyone on the Internet to read the memory of the systems protected by the vulnerable versions of the OpenSSL software. This compromises the secret keys used to identify
Metasploit
OpenSSL Heartbeat (Heartbleed) Client Memory Exposure
metasploit
OpenSSL Heartbeat (Heartbleed) Client Memory Exposure
OpenSSL Heartbeat (Heartbleed) Client Memory Exposure
This module provides a fake SSL service that is intended to leak memory from client systems as they connect. This module is hardcoded for using the AES-128-CBC-SHA1 cipher.
Tenable
From Bugs to Breaches: 25 Significant CVEs As MITRE CVE Turns 25
blogs_tenable·2024-10-22
From Bugs to Breaches: 25 Significant CVEs As MITRE CVE Turns 25
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Sentinelone
OpenSSL 3 Critical Vulnerability | What Do Organizations Need To Do Now?
blogs_sentinelone·2022-10-31·CVSS 7.5
CVE-2022-3786 [HIGH] OpenSSL 3 Critical Vulnerability | What Do Organizations Need To Do Now?
Last week, the OpenSSL project team announced the release of OpenSSL version 3.0.7, which was made available on Tuesday, November 1st. The update is a security fix for two vulnerabilities in OpenSSL 3.0.x, and developers and organizations are being urged to ensure that they patch any instances of OpenSSL 3 in their software stack as a matter of urgency. The vulnerabilities, CVE-2022-3786 and CVE-2022-3602, affect version 3.0.x and do not impact OpenSSL 1.1.1 or LibreSSL.
SentinelOne customers have instant visibility of OpenSSL versions within their organizations. As such, Singularity XDR is a useful visibility solution in ensuring your organization is ready for the OpenSSL 3 update.
## What is OpenSSL?
OpenSSL is an open-source cryptography library widely used by applications, operating
Sentinelone
OpenSSL 3 Critical Vulnerability | What Do Organizations Need To Do Now?
blogs_sentinelone·2022-10-31·CVSS 7.5
CVE-2022-3786 [HIGH] OpenSSL 3 Critical Vulnerability | What Do Organizations Need To Do Now?
Last week, the OpenSSL project team announced the release of OpenSSL version 3.0.7, which was made available on Tuesday, November 1st. The update is a security fix for two vulnerabilities in OpenSSL 3.0.x , and developers and organizations are being urged to ensure that they patch any instances of OpenSSL 3 in their software stack as a matter of urgency. The vulnerabilities, CVE-2022-3786 and CVE-2022-3602, affect version 3.0.x and do not impact OpenSSL 1.1.1 or LibreSSL.
SentinelOne customers have instant visibility of OpenSSL versions within their organizations. As such, Singularity XDR is a useful visibility solution in ensuring your organization is ready for the OpenSSL 3 update.
## What is OpenSSL?
OpenSSL is an open-source cryptography library widely used by applications, operatin
Tenable
Cybersecurity Snapshot: 6 Things That Matter Right Now
blogs_tenable·2022-07-15
Cybersecurity Snapshot: 6 Things That Matter Right Now
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Securing Critical Infrastructure: What We've Learned from Recent Incidents
blogs_tenable·2022-07-14
Securing Critical Infrastructure: What We've Learned from Recent Incidents
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Trendmicro
Drupal Bug Exploited to Deliver Monero-Mining Malware
blogs_trendmicro·2018-06-21·CVSS 9.8
CVE-2018-7602 [CRITICAL] Drupal Bug Exploited to Deliver Monero-Mining Malware
Malware
# Drupal Bug Exploited to Deliver Monero-Mining Malware
We were able to observe a series of network attacks exploiting, a security flaw (CVE-2018-7602) in the Drupal content management framework. For now, these attacks aim to turn affected systems into Monero-mining bots.
By: Smart Home Network Team, IoT Reputation Service Team
2018/06/21
Read time: ( words)
Save to Folio
We were able to observe a series of network attacks exploiting CVE-2018-7602, a security flaw in the Drupal content management framework. For now, these attacks aim to turn affected systems into Monero-mining bots. Of note are its ways of hiding behind the Tor network to elude detection and how it checks the affected system first before infecting it with a cryptocurrency-mining malware. While these attacks c
Trendmicro
Identifying Top Vulnerabilities in Networks
blogs_trendmicro·2018-05-29
Identifying Top Vulnerabilities in Networks
IoT
# Identifying Top Vulnerabilities in Networks
Our findings homed in on known vulnerabilities, IoT botnets with top vulnerability detections, and devices that are affected. Our scanning covered different OSs, including Linux, Mac, Windows, Android, iOS, and other SDK platforms.
By: Tony Yang, Adam Huang, Louis Tsai
2018/05/29
Read time: ( words)
Save to Folio
We have noted time and again how compromising networks and connected devices is rooted in finding weak points in the system. Often, these are in the form of vulnerabilities. Worse, vulnerabilities that aren’t even new. In the context of the internet of things (IoT) and noteworthy security incidents related to it, these vulnerabilities have afforded attackers means to use unsecure devices to facilitate malicious activities suc
Fortinet
Threat Intelligence Roundup September 09, 2016
blogs_fortinet·2016-09-09·CVSS 7.5
[HIGH] Threat Intelligence Roundup September 09, 2016
INDUSTRY TRENDS & INSIGHTS
Threat Intelligence Roundup September 09, 2016
By Bill McGee | September 09, 2016
This is our third week of the roundup, and things in the cyberthreat world continue to be interesting, including the return of several attacks we have seen for years. Here’s a quick summary of what happened this week.
1. It’s Still About Ransomware. While last week’s spike seems to have calmed down, we are still seeing an alarming amount of ransomware. This week our top 10 detections were all Javascript-based variants of Nemucod, with nearly 7 million attempts logged. It seems like attackers are producing a new Nemucod variant nearly every day
2. Social Engineering Makes a Comeback. On the heels of everyone getting back to school, often with shiny new laptops in place, we detect
Tenable
Remediation Prioritization with Curated Vulnerabilities using Nessus (aka #CaughtWithPantsDown)
blogs_tenable·2015-10-14
Remediation Prioritization with Curated Vulnerabilities using Nessus (aka #CaughtWithPantsDown)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Remediation Prioritization with Curated Vulnerabilities using Nessus (aka #CaughtWithPantsDown)
blogs_tenable·2015-10-14
Remediation Prioritization with Curated Vulnerabilities using Nessus (aka #CaughtWithPantsDown)
Blog /
Subscribe
# Remediation Prioritization with Curated Vulnerabilities using Nessus (aka #CaughtWithPantsDown)
Mehul Revankar
October 14, 2015
6 Min Read
Almost every day we face the constant challenge of choosing from things that need our urgent attention and ones that are important. How we classify and prioritize these items largely reflects our true character. Procrastinate enough, and it doesn't take long for important items to become urgent. Fail to distinguish urgent items from the important, and it could lead to catastrophic failure. In short, identifying our priorities and executing them in our daily workflow is the key to success in any walk of life. And when it comes to vulnerability management, it’s no different.
Identifying our priorities and executing them in our dai
Qualys
US-CERT: Top 30 Vulnerabilities | Qualys
blogs_qualys·2015-05-01·CVSS 2.6
[LOW] US-CERT: Top 30 Vulnerabilities | Qualys
On April 29, 2015 US-CERT published TA15-119A which describes the Top 30 vulnerabilities that critical infrastructure organizations should focus on because they are under attack all the time. The list contains Windows, Internet Explorer, Adobe Software from Reader, Flash to Cold Fusion, Java from Oracle and others and is quite similar to the more generic set of software packages published by the German BSI last December.
Here is a list of the vulnerabilities in the advisory. I have reordered and optimized where possible for efficient scanning with Qualys, for example listing the most recent patch first to take advantage of superseding patches:
- Windows: MS14-060 for CVE-2014-4114, Qualys ID: 90979
- Internet Explorer: MS14-021 for CVE-2014-1776, Qualys ID: 100191
- MS14-012 for CVE-201
Qualys
US-CERT: Top 30 Vulnerabilities | Qualys
blogs_qualys·2015-05-01·CVSS 2.6
[LOW] US-CERT: Top 30 Vulnerabilities | Qualys
On April 29, 2015 US-CERT published TA15-119A which describes the Top 30 vulnerabilities that critical infrastructure organizations should focus on because they are under attack all the time. The list contains Windows, Internet Explorer, Adobe Software from Reader, Flash to Cold Fusion, Java from Oracle and others and is quite similar to the more generic set of software packages published by the German BSI last December.
Here is a list of the vulnerabilities in the advisory. I have reordered and optimized where possible for efficient scanning with Qualys, for example listing the most recent patch first to take advantage of superseding patches:
Windows: MS14-060 for CVE-2014-4114, Qualys ID: 90979
MS14-012 for CVE-2014-0322
MS13-038 for CVE-2013-1347
MS13-008 for CVE-2012-4792
MS10-01
Unit42
Examining the CHS Breach and Heartbleed Exploitation
blogs_unit42·2014-08-20·CVSS 7.5
CVE-2014-0160 [HIGH] Examining the CHS Breach and Heartbleed Exploitation
## Examining the CHS Breach and Heartbleed Exploitation
Ryan Olson
Published: August 20, 2014
Malware
Threat Research
Vulnerabilities
Community Health Systems
CVE-2014-0160
Heartbleed
OpenSSL
TrustedSec
Yesterday, TrustedSec , a security consultancy based on Ohio, wrote that the recent breach at Community Health Systems (CHS) was the result of exploitation of the Heartbleed OpenSSL vulnerability (CVE-2014-0160). CHS’s 8-K filing on Monday did not reveal how the attackers got into their network, only that the records of approximately 4.5 million patients were stolen in attacks in between April and June of 2014. TrustedSec reports on how attackers were apparently able to glean user credentials from a certain device via the Heartbleed vulnerability and use them to log in via a VPN
Unit42
Examining the CHS Breach and Heartbleed Exploitation
blogs_unit42·2014-08-20·CVSS 7.5
CVE-2014-0160 [HIGH] Examining the CHS Breach and Heartbleed Exploitation
Yesterday, TrustedSec, a security consultancy based on Ohio, wrote that the recent breach at Community Health Systems (CHS) was the result of exploitation of the Heartbleed OpenSSL vulnerability (CVE-2014-0160). CHS’s 8-K filing on Monday did not reveal how the attackers got into their network, only that the records of approximately 4.5 million patients were stolen in attacks in between April and June of 2014. TrustedSec reports on how attackers were apparently able to glean user credentials from a certain device via the Heartbleed vulnerability and use them to log in via a VPN.
We need more facts to be sure, but this instance may be the first public breach related to the Heartbleed vulnerability since it was announced in April. Now, over four months since the Heartbleed disclosure, this
Unit42
8 Tips For Dealing With Heartbleed Right Now
blogs_unit42·2014-04-12·CVSS 7.5
CVE-2014-0160 [HIGH] 8 Tips For Dealing With Heartbleed Right Now
## 8 Tips For Dealing With Heartbleed Right Now
Rick Howard
Published: April 12, 2014
High Profile Threats
Vulnerabilities
CVE-2014-0160
Heartbleed
OpenSSL
This has been a fun week. We have not had a significant cyber event like this – something that affects just about everybody on the Internet -- since the Kaminsky DNS vulnerability of 2008 . Everybody I know has been scrambling to understand what it means to their organization, to their business and to their immediate family. Yes, I said family. I am sure I am not the only one who has answered a question or two from his mother-in-law about how the Internet is melting down based on what she’s been reading in the press.
There’s a lot out there already about what Heartbleed means for the Web and beyond, and I’ll point you to our o
Unit42
8 Tips For Dealing With Heartbleed Right Now
blogs_unit42·2014-04-12
8 Tips For Dealing With Heartbleed Right Now
This has been a fun week. We have not had a significant cyber event like this – something that affects just about everybody on the Internet -- since the Kaminsky DNS vulnerability of 2008. Everybody I know has been scrambling to understand what it means to their organization, to their business and to their immediate family. Yes, I said family. I am sure I am not the only one who has answered a question or two from his mother-in-law about how the Internet is melting down based on what she’s been reading in the press.
There’s a lot out there already about what Heartbleed means for the Web and beyond, and I’ll point you to our own analysis written by Scott Simkin or an essay by Dan Goodin over at ars technica for that explanation. Instead, here are eight things I am doing right now to protec
Tenable
Tenable Facilitates Detection of OpenSSL Vulnerability Using Nessus and Nessus Perimeter Service
blogs_tenable·2014-04-09
Tenable Facilitates Detection of OpenSSL Vulnerability Using Nessus and Nessus Perimeter Service
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Tenable Facilitates Detection of OpenSSL Vulnerability Using Nessus and Nessus Perimeter Service
blogs_tenable·2014-04-09·CVSS 7.5
[HIGH] Tenable Facilitates Detection of OpenSSL Vulnerability Using Nessus and Nessus Perimeter Service
Blog /
Subscribe
# Tenable Facilitates Detection of OpenSSL Vulnerability Using Nessus and Nessus Perimeter Service
Jeffrey Man
April 9, 2014
2 Min Read
Facilitate easy detection of the OpenSSL Heartbeat vulnerability in your enterprise
Note: Passive Vulnerability Scanner (PVS) is now Nessus Network Monitor. To learn more about this application and its latest capabilities, visit the Nessus Network Monitor web page.
Tenable Network Security® released plugins for the detection of the OpenSSL heartbeat vulnerability (aka the “Heartbleed Vulnerability”) on the 8th of April for Nessus® and the Passive Vulnerability Scanner™ (PVS™). A plugin for detecting the vulnerability in Apache web server logs has also been added to the Log Correlation Engine™ (LCE™) and available for reporting in Se
Huntress
CVE-2014-0160 Vulnerability: Analysis, Impact, Mitigation | Huntress
blogs_huntress·CVSS 7.5
CVE-2014-0160 [HIGH] CVE-2014-0160 Vulnerability: Analysis, Impact, Mitigation | Huntress
## CVE-2014-0160 Vulnerability
Published: 11/21/2025
Written by: Lizzie Danielson
## What is CVE-2014-0160 vulnerability?
CVE-2014-0160, widely known as the Heartbleed vulnerability, is a critical security flaw in the OpenSSL cryptographic software library. It is classified as a buffer over-read vulnerability, which allows attackers to exploit improperly implemented TLS/DTLS heartbeat functions to access sensitive data in memory. This data can include private keys, passwords, session cookies, and other sensitive information, leading to potential compromise of confidentiality and system integrity.
## When was it discovered?
Heartbleed was disclosed publicly on April 7, 2014, by researchers from Codenomicon and Google Security. It was identified shortly before that by Neel Mehta of Goo
Huntress
What is CVSS? Vulnerability Scoring Guide for Security Teams | Huntress
blogs_huntress
What is CVSS? Vulnerability Scoring Guide for Security Teams | Huntress
## Understanding CVSS: The Basics
Think of CVSS as a report card for vulnerabilities. Just like grades help teachers identify which students need the most attention, CVSS scores help security teams figure out which vulnerabilities deserve immediate action.
The scoring system ranges from 0 to 10, with severity levels that look like this:
0.0 : None
0.1-3.9 : Low
4.0-6.9 : Medium
7.0-8.9 : High
9.0-10.0 : Critical
But here's the thing—CVSS isn't just pulling numbers out of thin air. These scores are calculated using specific metrics that evaluate how exploitable a vulnerability is and what kind of damage it could cause.
## The Three Pillars of CVSS Scoring
## Base Metrics: The Foundation
Base metrics focus on the inherent characteristics of a vulnerability. They're like the DNA of
arXiv
Focus on What Matters: Fisher-Guided Adaptive Multimodal Fusion for Vulnerability Detection
arxiv_fulltext·2026-01-20
Focus on What Matters: Fisher-Guided Adaptive Multimodal Fusion for Vulnerability Detection
Focus on What Matters: Fisher-Guided Adaptive Multimodal Fusion for Vulnerability Detection
Yun Bian
Affiliated with University of Chinese Academy of Sciences, Beijing, China.
Chengdu Institute of Computer Applications, Chinese Academy of Sciences
Chengdu
China
[email protected]
Yi Chen
[1]
Chengdu Institute of Computer Applications, Chinese Academy of Sciences
Chengdu
China
[email protected]
HaiQuan Wang
[1]
Chengdu Institute of Computer Applications, Chinese Academy of Sciences
Chengdu
China
[email protected]
Shihao Li
[1]
Chengdu Institute of Computer Applications, Chinese Academy of Sciences
Chengdu
China
[email protected]
Zhe Cui
[1]
Corresponding author.
Chengdu Institute of Computer Applications, Chinese Academy of Sciences
Chengdu
Chi
arXiv
KryptoPilot: An Open-World Knowledge-Augmented LLM Agent for Automated Cryptographic Exploitation
arxiv_fulltext·2026-01-14
KryptoPilot: An Open-World Knowledge-Augmented LLM Agent for Automated Cryptographic Exploitation
KryptoPilot: An Open-World Knowledge-Augmented LLM Agent for Automated Cryptographic Exploitation
Xiaonan Liu
These authors contributed equally to this work.
Independent Researcher
Beijing
China
[email protected]
Zhihao Li
[1]
Sichuan University
Chengdu
China
[email protected]
Xiao Lan
Corresponding author.
Sichuan University
Chengdu
China
[email protected]
Hao Ren
Sichuan University
Chengdu
China
[email protected]
Haizhou Wang
Sichuan University
Chengdu
China
[email protected]
Xingshu Chen
Sichuan University
Chengdu
China
[email protected]
## Abstract
Capture-the-Flag (CTF) competitions play a central role in modern cybersecurity, serving as a primary platform for training security practitioners and evaluating offensive and defensive techniques derived f
arXiv
Automated Side-Channel Analysis of Cryptographic Protocol Implementations
arxiv_fulltext·2025-11-17
Automated Side-Channel Analysis of Cryptographic Protocol Implementations
Automated Side-Channel Analysis of Cryptographic Protocol Implementations
tabular[t]c
Faezeh Nasrabadi
CISPA Helmholtz Center for
Information Security &
Saarland University
[email protected]
tabular
0.5cm
tabular[t]c
Robert Künnemann
CISPA Helmholtz Center for
Information Security
[email protected]
tabular
0.5cm
tabular[t]c
Hamed Nemati
Department of Computer Science
KTH Royal Institute of Technology
[email protected]
tabular
## Abstract
We extract the first formal model of WhatsApp from its implementation by combining binary-level analysis (via ) with reverse engineering (via Ghidra) to handle this large closed-source application.
Using this model, we prove forward secrecy, identify a known clone-attack against post-compromise security and discover functional g
arXiv
Real-World Usability of Vulnerability Proof-of-Concepts: A Comprehensive Study
arxiv_fulltext·2025-10-21
Real-World Usability of Vulnerability Proof-of-Concepts: A Comprehensive Study
Real-World Usability of Vulnerability Proof-of-Concepts: A Comprehensive Study
Wenjing Dang, Kaixuan Li, Member, IEEE, Sen Chen, Member, IEEE, Zhenwei Zhuo, \ Zhang, Member, IEEE, and Zheli Liu, Member, IEEE
Wenjing Dang and Kaixuan Li contributed equally to this work.
Wenjing Dang and Zhenwei Zhuo are with the College of Intelligence and Computing, Tianjin University, China. Kaixuan Li and Lyuye Zhang are with the Nanyang Technological University, Singapore. Sen Chen (Corresponding author) and Zheli Liu are with the Nankai University, China. (email: [email protected]; [email protected]; [email protected]; [email protected]; [email protected]; [email protected])
## Abstract
The Proof-of-Concept (PoC) for a vulnerability is crucial in validating its existence, m
arXiv
DASICS White Paper: Enhancing Memory Protection with Dynamic Compartmentalization
arxiv_fulltext·2025-09-27
DASICS White Paper: Enhancing Memory Protection with Dynamic Compartmentalization
DASICS: Enhancing Memory Protection with Dynamic Compartmentalization
Yue Jin
Yibin Xu
Chengyuan Yang
Han Wang
Tianyi Huang
Tianyue Lu
Mingyu Chen
Institute of Computing Technology, Chinese Academy of Sciences
Beijing, China
whitepaper
## Abstract
In the existing software development ecosystem, security issues introduced by third-party code cannot be overlooked. Among these security concerns, memory access vulnerabilities stand out prominently, leading to risks such as the theft or tampering of sensitive data. To address this issue, software-based defense mechanisms have been established at the programming language, compiler, and operating system levels. However, as a trade-off, these mechanisms significantly reduce software execution efficiency. Hardware-software co-design app
arXiv
xOffense: An AI-driven autonomous penetration testing framework with offensive knowledge-enhanced LLMs and multi agent systems
arxiv_fulltext·2025-09-16
xOffense: An AI-driven autonomous penetration testing framework with offensive knowledge-enhanced LLMs and multi agent systems
1
.001
xOffense: An AI-driven autonomous penetration testing framework with offensive knowledge-enhanced LLMs and multi agent systems
[1]organization=Information Security Lab, University of Information Technology,
city=Ho Chi Minh City,
country=Vietnam
[2]organization=Vietnam National University Ho Chi Minh City,
city=Ho Chi Minh City,
country=Vietnam
[1,2]Phung Duc Luong 0009-0004-6057-5313
[email protected]
[1,2]Le Tran Gia Bao 0009-0000-8911-5741
[email protected]
[1,2]Nguyen Vu Khai Tam
0009-0008-1715-4213
[email protected]
[1,2]Dong Huu Nguyen Khoa 0009-0005-9526-140X
[email protected]
[1,2]Nguyen Huu Quyen 0000-0002-0065-9919
[email protected]
[1,2]Van-Hau Pham 0000-0003-3147-3356
[email protected]
[1,2]Phan The Duy 0000-0002-5945-3712cor1
[email protected]
arXiv
Uplifted Attackers, Human Defenders: The Cyber Offense-Defense Balance for Trailing-Edge Organizations
arxiv_fulltext·2025-08-14
Uplifted Attackers, Human Defenders: The Cyber Offense-Defense Balance for Trailing-Edge Organizations
-30pt
footnote0
## Abstract
Advances in artificial intelligence are widely understood to have implications for cybersecurity. Articles have emphasized the effect of AI on the cyber offense-defense balance, and credible commentators can be found arguing either that cyber will privilege attackers or defenders. For defenders, arguments are often made that AI will enable solutions like formal verification of all software—and for some well-equipped companies, this may be true. This conversation, however, does not match the reality for most companies. ``Trailing-edge organizations,'' as we term them, rely heavily on legacy software, poorly staff security roles, and struggle to implement best practices like rapid deployment of security patches. These decisions may be the result of corporate ine
arXiv
Enterprise Security Incident Analysis and Countermeasures Based on the T-Mobile Data Breach
arxiv_fulltext·2025-07-17
Enterprise Security Incident Analysis and Countermeasures Based on the T-Mobile Data Breach
## Abstract
This paper presents a comprehensive analysis of T-Mobile’s critical data breaches in 2021 and 2023, alongside a full-spectrum security audit targeting its systems, infrastructure, and publicly exposed endpoints. By combining case-based vulnerability assessments with active ethical hacking techniques—including Shodan reconnaissance, API misuse simulations, VNC brute-forcing, firmware reverse engineering, and web application scans—we uncover structural weaknesses persisting beyond the initial breach events. Building on these findings, we propose a multi-layered defensive strategy encompassing Zero Trust Architecture, granular role-based access control, network segmentation, firmware encryption using AES with integrity checks, and API rate limiting and token lifecycle control. Fi
arXiv
NanoZone: Scalable, Efficient, and Secure Memory Protection for Arm CCA
arxiv_fulltext·2025-06-08
NanoZone: Scalable, Efficient, and Secure Memory Protection for Arm CCA
: Scalable, Efficient, and Secure Memory Protection for Arm CCA
@IEEEauthorhalign
@IEEEauthorhalign
Shiqi Liu12,
Yongpeng Gao1,
Mingyang Zhang1,
Jie Wang1
The corresponding author.
1Huazhong University of Science and Technology
2George Mason University
[email protected], \sternen_hust, zoneshiyi, wangjie_s\@hust.edu.cn
1 The full name of the affiliation is Hubei Key Laboratory of Distributed System Security, Hubei Engineering Research Center on Big Data Security, School of Cyber Science and Engineering, Huazhong University of Science and Technology.
## Abstract
Arm Confidential Computing Architecture (CCA) currently isolates at the granularity of an entire Confidential Virtual Machine (CVM), leaving intra-VM bugs such as Heartbleed unmitigated. The state-of-the-art narrows this to the p
arXiv
A Slicing-Based Approach for Detecting and Patching Vulnerable Code Clones
arxiv_fulltext·2025-05-05
A Slicing-Based Approach for Detecting and Patching Vulnerable Code Clones
A Slicing-Based Approach for Detecting and Patching Vulnerable Code Clones
1st Hakam W. Alomari,
2nd Christopher Vendome,
3rd Himal Gyawali
Department of Computer Science and Software Engineering
Miami University, Oxford, Ohio USA
\alomarhw, vendomcg, gyawalh\@miamioh.edu
## Abstract
Code cloning is a common practice in software development, but it poses significant security risks by propagating vulnerabilities across cloned segments. To address this challenge, we introduce srcVul, a scalable, precise detection approach that combines program slicing with Locality-Sensitive Hashing to identify vulnerable code clones and recommend patches. srcVul builds a database of vulnerability-related slices by analyzing known vulnerable programs and their corresponding patches, indexing each slice
arXiv
VulRG: Multi-Level Explainable Vulnerability Patch Ranking for Complex Systems Using Graphs
arxiv_fulltext·2025-02-16
VulRG: Multi-Level Explainable Vulnerability Patch Ranking for Complex Systems Using Graphs
VulRG: Multi-Level Explainable Vulnerability Patch Ranking for Complex Systems Using Graphs
Yuning Jiang
[email protected]
0000-0003-4791-8452
National University of Singapore
Singapore
Nay Oo
[email protected]
NCS Cyber Special Ops R&D
Singapore
Qiaoran Meng
[email protected]
National University of Singapore
Singapore
Hoon Wei Lim
[email protected]
NCS Cyber Special Ops R&D
Singapore
Biplab Sikdar
[email protected]
National University of Singapore
Singapore
Jiang et al.
## Abstract
As interconnected systems proliferate, safeguarding complex infrastructures against an escalating array of cyber threats has become an urgent challenge. The growing number of vulnerabilities, coupled with resource constraints, makes addressing every vulnerability impractical, thereby rende
arXiv
Tracking Down Software Cluster Bombs: A Current State Analysis of the Free/Libre and Open Source Software (FLOSS) Ecosystem
arxiv_fulltext·2025-02-12
Tracking Down Software Cluster Bombs: A Current State Analysis of the Free/Libre and Open Source Software (FLOSS) Ecosystem
frontmatter
Tracking Down Software Cluster Bombs: A Current State Analysis of the Free/Libre and Open Source Software (FLOSS) Ecosystem
[1,2]0000-0002-2288-9010 Stefan Tatschnercor1
[1,3,4]0000-0002-1094-4828 Michael P. Heinl
[2]0009-0008-0767-8208 Nicole Pappler
[1]0009-0001-7615-7579 Tobias Specht
[5]0000-0002-1658-1140 Sven Plaga
[2]0000-0002-3375-8200 Thomas Newe
[cor1]Corresponding author
[1]organization=Fraunhofer AISEC,
city=Garching bei München,
state=Bavaria,
country=Germany
[2]organization=University of Limerick,
city=Limerick,
addressline=V94 T9PX,
country=Ireland
[3]organization=Technical University of Munich,
city=Garching bei München,
state=Bavaria,
country=Germany
[4]organization=Munich University of Applied Sciences HM,
city=Munich,
state=Bavaria,
country=Germany
[5]org
arXiv
Protecting Cryptographic Libraries against Side-Channel and Code-Reuse Attacks
arxiv_fulltext·2024-12-26
Protecting Cryptographic Libraries against Side-Channel and Code-Reuse Attacks
Protecting Cryptographic Libraries against Side-Channel and
Code-Reuse Attacks
Rodothea Myrsini Tsoupidi, [email protected]
Independent Researcher^*, Stockholm, Sweden
Elena Troubitsyna, [email protected]
KTH Royal Institute of Technology, Stockholm, Sweden
Panos Papadimitratos, [email protected]
KTH Royal Institute of Technology, Stockholm, Sweden
THEME/FEATURE/DEPARTMENTTHEME/FEATURE/DEPARTMENT
## Abstract
-1
Cryptographic libraries, an essential part of cybersecurity, are shown
to be susceptible to different types of attacks, including
side-channel and memory-corruption attacks.
In this article, we examine popular cryptographic libraries in terms
of the security measures they implement, pinpoint security
vulnerabilities, and suggest security improvements in their
development process.\
arXiv
Microservice Vulnerability Analysis: A Literature Review with Empirical Insights
arxiv_fulltext·2024-07-31
Microservice Vulnerability Analysis: A Literature Review with Empirical Insights
Microservice Vulnerability Analysis: A Literature Review with Empirical Insights
Raveen Kanishka Jayalath*
University of Adelaide, Australia
[email protected]
Hussain Ahmad* *Authors contributed equally to this work. Corresponding author.
University of Adelaide, Australia
[email protected]
Diksha Goel
CSIRO's Data61, Australia
[email protected]
3cmMuhammad Shuja Syed
3cmSLB, USA
[email protected]
Faheem Ullah
University of Adelaide, Australia
[email protected]
plain
## Abstract
Microservice architectures are revolutionizing both small businesses and large corporations, igniting a new era of innovation with their exceptional advantages in maintainability, reusability, and scalability. However, these benefits come w
arXiv
Security Vulnerability Detection with Multitask Self-Instructed Fine-Tuning of Large Language Models
arxiv_fulltext·2024-06-09
Security Vulnerability Detection with Multitask Self-Instructed Fine-Tuning of Large Language Models
Security Vulnerability Detection with Multitask Self-Instructed Fine-Tuning of Large Language Models
Aidan Z.H. Yang
[email protected]
Carnegie Mellon University
Pittsburgh
United States
Haoye Tian
[email protected]
University of Melbourne
Melbourne
Australia
He Ye
[email protected]
Carnegie Mellon University
Pittsburgh
United States
Ruben Martins
[email protected]
Carnegie Mellon University
Pittsburgh
United States
Claire Le Goues
[email protected]
Carnegie Mellon University
Pittsburgh
United States
## Abstract
Software security vulnerabilities allow attackers to perform malicious activities to disrupt software operations. Recent Transformer-based language models have significantly advanced vulnerability detection, surpassing the capabilities of static analysis based deep lear
arXiv
ParsEval: Evaluation of Parsing Behavior using Real-world Out-in-the-wild X.509 Certificates
arxiv_fulltext·2024-05-29
ParsEval: Evaluation of Parsing Behavior using Real-world Out-in-the-wild X.509 Certificates
ParsEval: Evaluation of Parsing Behavior using Real-world Out-in-the-wild X.509 Certificates
Stefan Tatschner
0000-0002-2288-9010
Fraunhofer Institute AISEC
Lichtenbergstraße 11
Garching bei München
Germany
85748
University of Limerick
Limerick
Ireland
[email protected]
Sebastian N. Peters
0009-0007-6421-4023
Technical University of Munich
Garching bei München
Germany
Fraunhofer Institute AISEC
Lichtenbergstraße 11
Garching bei München
Germany
85748
[email protected]
Michael P. Heinl
0000-0002-1094-4828
Technical University of Munich
Garching bei München
Germany
Fraunhofer Institute AISEC
Lichtenbergstraße 11
Garching bei München
Germany
85748
[email protected]
Tobias Specht
0009-0001-7615-7579
Fraunhofer Institute AISE
arXiv
Dynamic Neural Control Flow Execution: An Agent-Based Deep Equilibrium Approach for Binary Vulnerability Detection
arxiv_fulltext·2024-04-03
Dynamic Neural Control Flow Execution: An Agent-Based Deep Equilibrium Approach for Binary Vulnerability Detection
Dynamic Neural Control Flow Execution: An Agent-Based Deep Equilibrium Approach for Binary Vulnerability Detection
[1]Litao Li
[1]Steven H. H. Ding
[2]Andrew Walenstein
[3]Philippe Charland
[4]Benjamin C. M. Fung
[1]L1NNA Lab, School of Computing, Queen's University, Canada
[2]BlackBerry Ltd., Canada
[3]Mission Critical Cyber Security Section, Defence R&D Canada
[4]Data Mining and Security (DMaS) Lab, McGill University, Canada
## Abstract
Software vulnerabilities are a challenge in cybersecurity. Manual security patches are often difficult and slow to be deployed, while new vulnerabilities are created. Binary code vulnerability detection is less studied and more complex compared to source code, and this has important practical implications. Deep learning has become an efficient and powe
arXiv
One for All and All for One: GNN-based Control-Flow Attestation for Embedded Devices
arxiv_fulltext·2024-03-12
One for All and All for One: GNN-based Control-Flow Attestation for Embedded Devices
One for All and All for One:\ -based Control-Flow Attestation for Embedded Devices
Marco Chilese1, Richard Mitev1, Meni Orenbach2,
Robert Thorburn3, Ahmad Atamli23, Ahmad-Reza Sadeghi1 5px
1Technical University of Darmstadt, 2NVIDIA, 3 University of Southampton
## Abstract
Control-Flow Attestation (CFA) is a security service that allows an entity (verifier) to verify the integrity of code execution on a remote computer system (prover). Existing CFA schemes suffer from impractical assumptions, such as requiring access to the prover's internal state (e.g., memory or code), the complete Control-Flow Graph (CFG) of the prover's software, large sets of measurements, or tailor-made hardware. Moreover, current CFA schemes are inadequate for attesting embedded systems due to their high computat
arXiv
Cybersecurity as a Service
arxiv_fulltext·2024-02-21
Cybersecurity as a Service
Cybersecurity as a Service
John Morris^* Stefan Tatschner^* Michael P. Heinl Patrizia Heinl Thomas Newe Sven Plaga
*These authors contributed equally to this work.
Authors:
- John Morris^*; Department of Electronic and Computer Engineering, University of Limerick, Ireland; [email protected]; ORCID: https://orcid.org/0000-0003-2811-1055
- Stefan Tatschner^* Fraunhofer AISEC, Department Product Protection and Industrial Security, Germany; Department of Electronic and Computer Engineering, University of Limerick, Ireland; Confirm, the SFI Centre for Smart Manufacturing, Ireland;
[email protected]; ORCID: https://orcid.org/0000-0002-2288-9010
- Michael P. Heinl; Fraunhofer AISEC, Department Product Protection and Industrial Security, Germany; [email protected]
arXiv
CryptoBap: A Binary Analysis Platform for Cryptographic Protocols
arxiv_fulltext·2023-09-18
CryptoBap: A Binary Analysis Platform for Cryptographic Protocols
: A Binary Analysis Platform for Cryptographic Protocols
Faezeh Nasrabadi
CISPA Helmholtz Center for Information Security
0009-0005-3659-7755
[email protected]
Robert Künnemann
CISPA Helmholtz Center for Information Security
0000-0003-0822-9283
[email protected]
Hamed Nemati
CISPA Helmholtz Center for Information Security
0000-0001-9251-3679
[email protected]
CCSXML
10002978.10002986.10002990
Security and privacy Logic and verification
500
CCSXML
[500]Security and privacy Logic and verification
## Abstract
We introduce , a platform to verify weak secrecy and authentication for the (ARMv8 and RISC-V) machine code of cryptographic protocols. We achieve this by first transpiling the binary of protocols into an intermediate representation and then performi
RFC
OAuth 2.0 Demonstrating Proof of Possession (DPoP)
rfc·2023-09-01
OAuth 2.0 Demonstrating Proof of Possession (DPoP)
Internet Engineering Task Force (IETF) D. Fett
Request for Comments: 9449 Authlete
Category: Standards Track B. Campbell
ISSN: 2070-1721 Ping Identity
J. Bradley
Yubico
T. Lodderstedt
Tuconic
M. Jones
Self-Issued Consulting
D. Waite
Ping Identity
September 2023
OAuth 2.0 Demonstrating Proof of Possession (DPoP)
Abstract
This document describes a mechanism for sender-constraining OAuth 2.0
tokens via a proof-of-possession mechanism on the application level.
This mechanism allows for the detection of replay attacks with access
and refresh tokens.
Status of This Memo
This is an Internet Standards Track document.
This document is a product of the Internet Engineering Task Force
(IETF). It represents the consensus of the IETF community. It has
received public review and has been appr
arXiv
ChatGPT for Digital Forensic Investigation: The Good, The Bad, and The Unknown
arxiv_fulltext·2023-07-10
ChatGPT for Digital Forensic Investigation: The Good, The Bad, and The Unknown
frontmatter
ChatGPT for Digital Forensic Investigation: The Good, The Bad, and The Unknown
[add1]Mark Scanlonfirstcorr
[email protected]
[firstcorr]Corresponding author
[add1]Forensics and Security Research Group, School of Computer Science, University College Dublin, Ireland
[add2]Frank Breitinger
[email protected]
[add2]School of Criminal Justice, University of Lausanne, Lausanne, Switzerland
[add3]Christopher Hargreaves
[email protected]
[add3]Department of Computer Science, University of Oxford, United Kingdom
[add4]Jan-Niclas Hilgert
[email protected]
[add4]Fraunhofer FKIE, Bonn, Germany
[add5]John Sheppard
[email protected]
[add5]Department of Computing and Mathematics, South East Technological University, Waterford, Ireland
## Abstract
arXiv
Cerberus: Exploring Federated Prediction of Security Events
arxiv_fulltext·2022-09-07
Cerberus: Exploring Federated Prediction of Security Events
: Exploring Federated Prediction of Security Events Published in ACM CCS 2022. Please cite the CCS version.
Mohammad Naseri
University College London
[email protected]
Yufei Han
Inria Rennes
[email protected]
Enrico Mariconti
University College London
[email protected]
Yun Shen
Work partially done while the author was with NortonLifeLock.
NetApp
[email protected]
Gianluca Stringhini
Boston University
[email protected]
Emiliano De Cristofaro
University College London
[email protected]
## Abstract
Modern defenses against cyberattacks increasingly rely on proactive approaches, e.g., to predict the adversary's next actions based on past events.
Building accurate prediction models requires knowledge from many organizations; alas, this entails disclosing sen
arXiv
A Review on C3I Systems' Security: Vulnerabilities, Attacks, and Countermeasures
arxiv_fulltext·2022-01-31
A Review on C3I Systems' Security: Vulnerabilities, Attacks, and Countermeasures
A Review on C3I Systems' Security: Vulnerabilities, Attacks, and Countermeasures
Hussain Ahmad
[email protected]
CREST - The Centre for Research on Engineering Software Technologies, The University of Adelaide, CSCRC - Cyber Security Cooperative Research Centre
Australia
Isuru Dharmadasa
[email protected]
Faheem Ullah
[email protected]
CREST - The Centre for Research on Engineering Software Technologies, The University of Adelaide
Australia
M. Ali Babar
[email protected]
CREST - The Centre for Research on Engineering Software Technologies, The University of Adelaide, CSCRC - Cyber Security Cooperative Research Centre
Australia
Authors' addresses: Hussain Ahmad, [email protected]; Isuru Dharmadasa, isuru.mahaganiarach
arXiv
Polytope: Practical Memory Access Control for C++ Applications
arxiv_fulltext·2022-01-24
Polytope: Practical Memory Access Control for C++ Applications
[ ]Ioannis Agadakos
[ ]Manuel Egele
[ ]William Robertson
[ ]Northeastern University
[ ]Boston University
## Abstract
Abstract.
Designing and implementing secure software is inarguably more important than ever. However, despite years of research into privilege separating programs,
it remains difficult to actually do so and such efforts can take years of labor-intensive engineering to reach fruition.
At the same time, new intra-process isolation primitives make strong data isolation and privilege separation more attractive from a performance perspective.
Yet, substituting intra-process security boundaries for time-tested process boundaries opens the door to subtle but devastating privilege leaks.
In this work, we present , a language extension to C++ that aims to make efficient privilege
arXiv
Attack of the Clones: Measuring the Maintainability, Originality and Security of Bitcoin 'Forks' in the Wild
arxiv_fulltext·2022-01-21
Attack of the Clones: Measuring the Maintainability, Originality and Security of Bitcoin 'Forks' in the Wild
Attack of the Clones: Measuring the Maintainability, Originality and Security of Bitcoin `Forks' in the Wild
Attack of the Clones
Jusop Choi1 Wonseok Choi1 William Aiken1 Hyoungshick Kim1 Jun Ho Huh2 Taesoo Kim3 Yongdae Kim4 Ross Anderson5
Jusop Choi et al.
Sungkyunkwan University, Republic of Korea Samsung Research, Republic of Korea Georgia Institute of Technology, USA Korea Advanced Institute of Science and Technology, Republic of Korea Cambridge University, UK
## Abstract
Since Bitcoin appeared in 2009, over 6,000 different cryptocurrency projects have followed. The cryptocurrency world may be the only technology where a massive number of competitors offer similar services yet claim unique benefits, including scalability, fast transactions, and security. But are these projects real
arXiv
Revisiting Challenges for Selective Data Protection of Real Applications
arxiv_fulltext·2021-05-29
Revisiting Challenges for Selective Data Protection of Real Applications
Revisiting Challenges for Selective Data Protection of Real Applications
[1]Lin Ma
[1]Jinyan Xu
[1]Jiadong Sun
[1]Yajin ZhouCorresponding author ([email protected]). *0.4em
[1]Xun Xie
[1]Wenbo Shen
[1]Rui Chang
[1]Kui Ren
[1]Zhejiang University
## Abstract
Selective data protection is a promising technique to defend against the data leakage attack. In this paper, we revisit technical challenges that were neglected when applying this protection to real applications. These challenges include the secure input channel, granularity conflict, and sensitivity
conflict. We summarize the causes of them and propose corresponding solutions. Then we design and implement a prototype system for selective data protection and evaluate the overhead using the RISC-V Spike simulator. The evaluation de
CTF
Quack the Quackers / README
ctf_writeups·2020
Quack the Quackers / README
# Quack the Quackers - HackTM 2020 Quals
## Introduction
Quack the Quackers is a pwn task.
A company was compromised with a device similar to a rubber ducky (Hence the
duck references.). We are given a memory dump of this device.
The task consists of two parts : the first consists of reverse-engineering the
memory dump of the device, download the malware and analyze it. The second
consists of exploiting a vulnerability in the malware's command and control
(CnC) server.
## Reverse-engineering of the firmware
The device is said to be a `Digispark`. The firmware contains a mention of
`Digistump` and `Digispark`.
The [official wiki](http://digistump.com/wiki/digispark/tutorials/programming)
makes several mentions of `AVR` and `Attiny`.
Nobody wants to reverse AVR. Calling `strings` on
arXiv
TASE: Reducing latency of symbolic execution with transactional memory
arxiv_fulltext·2019-12-27
TASE: Reducing latency of symbolic execution with transactional memory
: Reducing Latency of Symbolic Execution with Transactional Memory
Adam Humphries1,
Kartik Cating-Subramanian2, and
Michael K.\ Reiter1
1University of North Carolina at Chapel Hill
2University of Colorado -- Boulder (work performed at UNC-Chapel Hill)
plain
plain
## Abstract
We present the design and implementation of a tool called
that uses transactional memory to reduce the latency of
symbolic-execution applications with small amounts of symbolic
state. Execution paths are executed natively while operating on
concrete values, and only when execution encounters symbolic values
(or modeled functions) is native execution suspended and
interpretation begun. Execution then returns to its native mode
when symbolic values are no longer encountered. The key innovations
in the design of are a
arXiv
SAFE: Self-Attentive Function Embeddings for Binary Similarity
arxiv_fulltext·2019-12-19
SAFE: Self-Attentive Function Embeddings for Binary Similarity
for Binary Similarity
Luca Massarelli^ , Giuseppe Antonio Di Luna^ , Fabio Petroni^*,
Leonardo Querzoni^ , Roberto Baldoni^
: University of Rome Sapienza. \massarelli, querzoni, baldoni\@diag.uniroma1.it.
: CINI, National Laboratory of Cyber Security. [email protected].
*: Facebook AI Research, [email protected].
## Abstract
The binary similarity problem consists in determining if two functions are similar by only considering their compiled form. Advanced techniques for binary similarity recently gained momentum as they can be applied in several fields, such as copyright disputes, malware analysis, vulnerability detection, etc., and thus have an immediate practical impact. Current solutions compare functions by first transforming their binary code in multi-dimensional vector repres
arXiv
Code-less Patching for Heap Vulnerabilities Using Targeted Calling Context Encoding
arxiv_fulltext·2018-12-11
Code-less Patching for Heap Vulnerabilities Using Targeted Calling Context Encoding
Code-less Patching for Heap Vulnerabilities Using Targeted Calling Context Encoding
comment
1st Given Name Surname
dept. name of organization (of Aff.)
name of organization (of Aff.)
City, Country
email address
2nd Given Name Surname
dept. name of organization (of Aff.)
name of organization (of Aff.)
City, Country
email address
3rd Given Name Surname
dept. name of organization (of Aff.)
name of organization (of Aff.)
City, Country
email address
4th Given Name Surname
dept. name of organization (of Aff.)
name of organization (of Aff.)
City, Country
email address
5th Given Name Surname
dept. name of organization (of Aff.)
name of organization (of Aff.)
City, Country
email address
6th Given Name Surname
dept. name of organization (of Aff.)
name of organization (of Aff.)
arXiv
Secure by default - the case of TLS
arxiv_fulltext·2017-08-24
Secure by default - the case of TLS
Secure by default -- the case of TLS
Martin Stanek \ 1ex]
Department of Computer Science
Comenius University
@dcs.fmph.uniba.sk
## Abstract
Default configuration of various software applications often neglects security objectives.
We tested the default configuration of TLS in dozen web and application servers.
The results show that ``secure by default'' principle should be adopted more broadly
by developers and package maintainers. In addition, system administrators cannot
rely blindly on default security options.
: TLS, secure defaults, testing.
## Introduction
Security often depends on prudent configuration of software components used in a deployed
system. All necessary security controls and options are there, but one have
to turn them on or simply start using them. Unfortunately
arXiv
Software-Defined Adversarial Trajectory Sampling
arxiv_fulltext·2017-04-30
Software-Defined Adversarial Trajectory Sampling
Software-Defined Adversarial\ Sampling
Kashyap Thimmaraju^1 Liron Schiff^2 Stefan Schmid^1,3
^1 TU Berlin, Germany
^2 GuardiCore Labs, Israel
^3 Aalborg University, Denmark
## Abstract
Today's routing protocols critically rely on the assumption
that the underlying hardware is trusted.
Given the increasing number of attacks on
network devices, and recent reports on hardware
backdoors this
assumption has become questionable.
Indeed, with the critical role computer networks play today,
the contrast between our security assumptions and reality is problematic.
This paper presents Software-Defined Adversarial Trajectory Sampling ( ),
an OpenFlow-based mechanism to efficiently
monitor packet trajectories, also
in the presence of non-cooperating or even adversarial
switches or routers, e.g.,
CTF
tr2-ssl-0day-20 / README
ctf_writeups·2017·CVSS 7.5
CVE-2014-0160 [HIGH] tr2-ssl-0day-20 / README
# AlexCTF: TR2: SSL 0day
**Category:** Trivia
**Points:** 20
**Solves:** 799
**Description:**
> It lead to memory leakage between servers and clients rending large number of
> private keys accessible. (one word)
## Write-up
As a challenge of recon, for those who don't know from memory, the first step is to search the world wide web for **SSL zero day** which (at least with Google) returns a results page plastered with the term **Heartbleed** (labeled as CVE-2014-0160). The flag is `AlexCTF{Heartbleed}`.
## Other write-ups and resources
* [Rawsec](http://rawsec.ml/en/AlexCTF-2017-write-ups/#20-TR2-SSL-0day-Trivia)
* [R3dCr3sc3nt](https://github.com/R3dCr3sc3nt/AlexCTF/blob/master/TR2-SSL_0day/README.md)
* [Serpent Skis](https://github.com/KevOrr/ctf-writeups/blob/master/alexctf-2017/t
arXiv
Server-side verification of client behavior in cryptographic protocols
arxiv_fulltext·2016-03-13·CVSS 7.5
[HIGH] Server-side verification of client behavior in cryptographic protocols
Server-side Verification of Client Behavior in Cryptographic Protocols
tabularccccc
Andrew Chi & Robert Cochran & Marie Nesfield & Michael K.\ Reiter & Cynthia Sturton\ 10pt]
5cUniversity of North Carolina
5cChapel Hill, NC, USA
tabular
empty
### Abstract
Numerous exploits of client-server protocols and applications involve
modifying clients to behave in ways that untampered clients would not,
such as crafting malicious packets. In this paper, we demonstrate
practical verification of a cryptographic protocol client's messaging
behavior as being consistent with the client program it is believed to
be running. Moreover, we accomplish this without modifying the client
in any way, and without knowing all of the client-side inputs driving
its behavior. Our toolchain for verifying a client'
CTF
code-name-10 / README
ctf_writeups·2016·CVSS 7.5
CVE-2014-0160 [HIGH] code-name-10 / README
# H4ckIT CTF 2016 : code-name-10
**Category:** quiz
**Points:** 10
**Solves:**
**Description:**
Columbia
> Code name of CVE-2014-0160? h4ck1t{answer(lowercase)}
## Write-up
Those familiar with common vulnerabilities and CVE identifiers may be able to recognize it on the spot, but Googling "CVE-2015-0160" leads you to the CVE entry, which in the description is labeled as Heartbleed.
## Other write-ups and resources
* none yet
CTF
attack-paths
ctf_writeups·CVSS 6.0
[MEDIUM] attack-paths
---
layout: default
title: Attack Paths
nav_order: 8
description: "Visual attack path flowcharts for popular HTB machines - from reconnaissance to root"
permalink: /attack-paths/
---
# Attack Path Diagrams
{: .fs-9 }
Visual flowcharts mapping the complete attack chain for 30 popular Hack The Box machines, from initial reconnaissance to root/SYSTEM.
{: .fs-6 .fw-300 }
---
## How to Read These Diagrams
Each diagram traces the full exploitation path for a machine using a top-down flowchart. The color coding indicates the phase of the attack:
- **Green nodes** - Reconnaissance and enumeration
- **Orange nodes** - Initial access / foothold
- **Blue nodes** - Post-exploitation and lateral movement
- **Red nodes** - Privilege escalation
- **Purple nodes** - Root or SYSTEM achieved
Nodes in
CTF
easy / README
ctf_writeups·CVSS 6.0
[MEDIUM] easy / README
---
layout: default
title: Easy Machines
parent: Machines
nav_order: 1
description: "120+ Easy HTB machine writeups with walkthroughs"
permalink: /machines/easy/
---
# HackTheBox Easy Machines - Comprehensive Reference
> Complete catalog of retired HTB Easy machines with OS, key vulnerability, attack path summary, and quality writeup links.
**Total: 100+ Easy Machines** | Updated: April 2026
---
## Quick Navigation
- [Classic / Legacy Machines (2017-2019)](#classic--legacy-machines-2017-2019)
- [2019-2020 Machines](#2019-2020-machines)
- [2021 Machines](#2021-machines)
- [2022 Machines](#2022-machines)
- [2023 Machines](#2023-machines)
- [2024 Machines (Season 4 & 5)](#2024-machines-season-4--5)
- [2025-2026 Machines (Season 6+)](#2025-2026-machines-season-6)
---
## Classic / Legac
CTF
09_evil / README
ctf_writeups
09_evil / README
# Flare-On 8, Challenge 9, evil
## Task
Mandiant's unofficial motto is "find evil and solve crime". Well here is evil but forget crime, solve challenge. Listen kid, RFCs are for fools, but for you we'll make an exception :)
The challenge has 3 false flags: `[email protected]` `[email protected]` `[email protected]`
## Files
Filename | Size | SHA256
--- | --- | ---
evil.exe | 2,964,480 bytes | 83902600c32ff5d37cbdbed813d99c3b05b0f53311170c3b8c39a4db958f8eaa
## High Level Summary
- evil.exe is a 32 Bit Windows PE binary that registers a Vectored Exception Handler (VEH) as a means of Control Flow Obfuscation.
- Whenever exceptions are intentionally raised by accessing memory offset 0 or by a division by zero, the VEH dynamically patch
CTF
heartbleed_fuzz / README
ctf_writeups·CVSS 7.5
CVE-2014-0160 [HIGH] heartbleed_fuzz / README
# OpenSSL Heartbleed Fuzz Example
We use this to examine and find a real-world vulnerability, CVE-2014-0160, aka Heartbleed, in OpenSSL. This was a prominent attack, but the actual root cause analysis shows how rudimentary the actual bug was (lack of a bounds check on dynamically allocated memory == OOB read).
# Setup
The build setup is replicated from [afl-training](https://github.com/mykter/afl-training), which is really nice for rapidly getting an environment setup to perform fuzzing on some targets.
Inside the vulnerable OpenSSL source:
```
$ CC=afl-clang CXX=afl-clang++ ./config
$ AFL_USE_ASAN=1 make
```
Building the target:
```
$ AFL_USE_ASAN=1 afl-clang-fast++ -g harness.cpp openssl/libssl.a openssl/libcrypto.a -o harness -I openssl/include -ldl
```
Running the fuzzer:
```
CTF
Valentine / README
ctf_writeups
Valentine / README
# Valentine
> Write-up author: jon-brandy
## STEPS:
> PORT SCANNING
```
┌──(brandy㉿bread-yolk)-[~/Downloads]
└─$ nmap -p- -sVC 10.10.10.79 --min-rate 1000
Starting Nmap 7.93 ( https://nmap.org ) at 2023-09-18 07:35 PDT
Nmap scan report for 10.10.10.79
Host is up (0.036s latency).
Not shown: 65532 closed tcp ports (conn-refused)
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 5.9p1 Debian 5ubuntu1.10 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
| 1024 964c51423cba2249204d3eec90ccfd0e (DSA)
| 2048 46bf1fcc924f1da042b3d216a8583133 (RSA)
|_ 256 e62b2519cb7e54cb0ab9ac1698c67da9 (ECDSA)
80/tcp open http Apache httpd 2.2.22 ((Ubuntu))
|_http-title: Site doesn't have a title (text/html).
|_http-server-header: Apache/2.2.22 (Ubuntu)
443/tcp open ssl/http Apache httpd 2.2.22 ((Ubuntu))
|_http-t
Bugzilla
tor: security update
bugzilla·2014-05-28·CVSS 7.5
CVE-2014-0160 [HIGH] tor: security update
tor: security update
Fedora (and EPEL) ship a bit outdated version of tor packages.
In fact, upstream is no longer maintaining tor version 0.2.3.x, and discourages its use [1].
More on this, 0.2.3.x lacks a fix for CVE-2014-0160 (Heartbleed).
0.2.4.x ChangeLog: https://gitweb.torproject.org/tor.git?a=blob_plain;hb=release-0.2.4;f=ReleaseNotes
[1]: https://bugzilla.novell.com/show_bug.cgi?id=878486#c0
Discussion:
Created tor tracking bugs for this issue:
Affects: fedora-all [bug 1102132]
Affects: epel-all [bug 1102136]
---
Created tor-arm tracking bugs for this issue:
Affects: fedora-all [bug 1102134]
---
(In reply to Vasyl Kaigorodov from comment #2)
> Created tor-arm tracking bugs for this issue:
>
> Affects: fedora-all [bug 1102134]
tor-arm is not the same thing as tor, so i
HackerOne
https://concrete5.org ::: HeartBleed Attack (CVE-2014-0160)
hackerone·2014-04-09·CVSS 7.5
CVE-2014-0160 [HIGH] https://concrete5.org ::: HeartBleed Attack (CVE-2014-0160)
https://concrete5.org ::: HeartBleed Attack (CVE-2014-0160)
Pls see attachment files for details:
python ssltest.py concrete5.org 443|more
impact: critical, pls patch it ASAP
References:
https://www.openssl.org/news/secadv_20140407.txt
http://heartbleed.com
https://github.com/openssl/openssl/commit/96db9023b881d7cd9f379b0c154650d6c108e9a3
~g4mm4
https://twitter.com/xchym
Bugzilla
OpenSSL version in Firefox OS builds vulnerable to CVE-2014-0160 ("Heartbleed")
bugzilla·2014-04-09·CVSS 7.5
CVE-2014-0160 [HIGH] OpenSSL version in Firefox OS builds vulnerable to CVE-2014-0160 ("Heartbleed")
OpenSSL version in Firefox OS builds vulnerable to CVE-2014-0160 ("Heartbleed")
Firefox includes a version of openssl from android which appears to be vulnerable to CVE-2014-0160. We include openssl in places like here [1] and from the source files I have checked so far, they seem all to be including version 1.0.1e, which is known to be vulnerable.
However there are some mitigating factors here:
- this is only an issue if we actually use openssl to recieve or initiate SSL
connections.
- server code is at higher risk of attack, since attacking client code relies on client connecting to malicious SSL server
As far as I know Gecko doesn't use openssl at all (nss instead) but I would like to make sure. Some things to check might be:
- nfcd
- vendor update mechanisms
For now, I am rating th
Bugzilla
CVE-2014-0160 openssl: information disclosure in handling of TLS heartbeat extension packets
bugzilla·2014-04-07·CVSS 7.5
CVE-2014-0160 [HIGH] CVE-2014-0160 openssl: information disclosure in handling of TLS heartbeat extension packets
CVE-2014-0160 openssl: information disclosure in handling of TLS heartbeat extension packets
A missing bounds check was found in the way OpenSSL handled TLS heartbeat extension packets. This flaw could be used to reveal up to 64k of memory from a connected client or server.
Only 1.0.1 releases of OpenSSL are affected including 1.0.1f (and 1.0.2 betas)
The following upstream commit introduced TLS/DTLS heatbeat support and also this issue:
http://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=4817504
Discussion:
Acknowledgements:
Red Hat would like to thank the OpenSSL project for reporting this issue. Upstream acknowledges Neel Mehta of Google Security as the original reporter.
---
Created attachment 883475
OpenSSL patch
---
External References:
http://www.openssl.org/news
Bugzilla
CVE-2014-0160 openssl: information disclosure in handling of TLS heartbeat extension packets [fedora-all]
bugzilla·2014-04-07·CVSS 7.5
CVE-2014-0160 [HIGH] CVE-2014-0160 openssl: information disclosure in handling of TLS heartbeat extension packets [fedora-all]
CVE-2014-0160 openssl: information disclosure in handling of TLS heartbeat extension packets [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Bugzilla
CVE-2014-0160 mingw-openssl: openssl: information disclosure in handling of TLS heartbeat extension packets [fedora-all]
bugzilla·2014-04-07·CVSS 7.5
CVE-2014-0160 [HIGH] CVE-2014-0160 mingw-openssl: openssl: information disclosure in handling of TLS heartbeat extension packets [fedora-all]
CVE-2014-0160 mingw-openssl: openssl: information disclosure in handling of TLS heartbeat extension packets [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field w
CWE
Improper Handling of Length Parameter Inconsistency
mitre_cwe
CWE-130 Improper Handling of Length Parameter Inconsistency
CWE-130: Improper Handling of Length Parameter Inconsistency
The product parses a formatted message or structure, but it does not handle or incorrectly handles a length field that is inconsistent with the actual length of the associated data.
If an attacker can manipulate the length parameter associated with an input such that it is inconsistent with the actual length of the input, this can be leveraged to cause the target application to behave in unexpected, and possibly, malicious ways. One of the possible motives for doing so is to pass in arbitrarily large input to the application. Another possible motivation is the modification of application state by including invalid data for subsequent properties of the application. Such weaknesses commonly lead to attacks such as buffer overflow
CWE
Buffer Over-read
mitre_cwe
CWE-126 Buffer Over-read
CWE-126: Buffer Over-read
The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.
Modes of Introduction:
Phase: Implementation
Common Consequences:
Scope: Confidentiality. Impact: Read Memory.
Scope: Confidentiality. Impact: Bypass Protection Mechanism. By reading out-of-bounds memory, an attacker might be able to get secret values, such as memory addresses, which can bypass protection mechanisms such as ASLR in order to improve the reliability and likelihood of exploiting a separate weakness to achieve code execution instead of just denial of service.
Scope: Availability, Integrity. Impact: DoS: Crash, Exit, or Restart. An attacker might be able to cause a crash or other denial of service by c
OWASP
Testing for Weak Transport Layer Security
owasp
Testing for Weak Transport Layer Security
# Testing for Weak Transport Layer Security
|ID |
|------------|
|WSTG-CRYP-01|
## Summary
When information is sent between the client and the server, it must be encrypted and protected in order to prevent an attacker from being able to read or modify it. This is most commonly done using HTTPS, which uses the [Transport Layer Security (TLS)](https://en.wikipedia.org/wiki/Transport_Layer_Security) protocol, a replacement for the older Secure Socket Layer (SSL) protocol. TLS also provides a way for the server to demonstrate to the client that they have connected to the correct server, by presenting a trusted digital certificate.
Over the years there have been a large number of cryptographic weaknesses identified in the SSL and TLS protocols, as well as in the ciphers that they use. Addit
CWE
Out-of-bounds Read
mitre_cwe
CWE-125 Out-of-bounds Read
CWE-125: Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
Modes of Introduction:
Phase: Implementation
Common Consequences:
Scope: Confidentiality. Impact: Read Memory. An attacker could get secret values such as cryptographic keys, PII, memory addresses, or other information that could be used in additional attacks.
Scope: Confidentiality. Impact: Bypass Protection Mechanism. Out-of-bounds memory could contain memory addresses or other information that can be used to bypass ASLR and other protection mechanisms in order to improve the reliability of exploiting a separate weakness for code execution.
Scope: Availability. Impact: DoS: Crash, Exit, or Restart. An attacker could cause a segmentation fault or crash by causing memory to
CWE
Improper Handling of Inconsistent Structural Elements
mitre_cwe·CVSS 5.0
[MEDIUM] CWE-240 Improper Handling of Inconsistent Structural Elements
CWE-240: Improper Handling of Inconsistent Structural Elements
The product does not handle or incorrectly handles when two or more structural elements should be consistent, but are not.
Modes of Introduction:
Phase: Implementation
Common Consequences:
Scope: Integrity, Other. Impact: Varies by Context, Unexpected State.
Examples:
In the following C/C++ example the method processMessageFromSocket() will get a message from a socket, placed into a buffer, and will parse the contents of the buffer into a structure that contains the message length and the message body. A for loop is used to copy the message body into a local character string which will be passed to another method for processing.
However, the message length variable (msgLength) from the structure is used as the condition for
http://advisories.mageia.org/MGASA-2014-0165.htmlhttp://blog.fox-it.com/2014/04/08/openssl-heartbleed-bug-live-blog/http://cogentdatahub.com/ReleaseNotes.htmlhttp://download.schneider-electric.com/files?p_Doc_Ref=SEVD%202014-119-01http://git.openssl.org/gitweb/?p=openssl.git%3Ba=commit%3Bh=96db9023b881d7cd9f379b0c154650d6c108e9a3http://heartbleed.com/http://lists.fedoraproject.org/pipermail/package-announce/2014-April/131221.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-April/131291.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-August/136473.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-04/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-04/msg00005.htmlhttp://lists.opensuse.org/opensuse-updates/2014-04/msg00061.htmlhttp://marc.info/?l=bugtraq&m=139722163017074&w=2http://marc.info/?l=bugtraq&m=139757726426985&w=2http://marc.info/?l=bugtraq&m=139757819327350&w=2http://marc.info/?l=bugtraq&m=139757919027752&w=2http://marc.info/?l=bugtraq&m=139758572430452&w=2http://marc.info/?l=bugtraq&m=139765756720506&w=2http://marc.info/?l=bugtraq&m=139774054614965&w=2http://marc.info/?l=bugtraq&m=139774703817488&w=2http://marc.info/?l=bugtraq&m=139808058921905&w=2http://marc.info/?l=bugtraq&m=139817685517037&w=2http://marc.info/?l=bugtraq&m=139817727317190&w=2http://marc.info/?l=bugtraq&m=139817782017443&w=2http://marc.info/?l=bugtraq&m=139824923705461&w=2http://marc.info/?l=bugtraq&m=139824993005633&w=2http://marc.info/?l=bugtraq&m=139833395230364&w=2http://marc.info/?l=bugtraq&m=139835815211508&w=2http://marc.info/?l=bugtraq&m=139835844111589&w=2http://marc.info/?l=bugtraq&m=139836085512508&w=2http://marc.info/?l=bugtraq&m=139842151128341&w=2http://marc.info/?l=bugtraq&m=139843768401936&w=2http://marc.info/?l=bugtraq&m=139869720529462&w=2http://marc.info/?l=bugtraq&m=139869891830365&w=2http://marc.info/?l=bugtraq&m=139889113431619&w=2http://marc.info/?l=bugtraq&m=139889295732144&w=2http://marc.info/?l=bugtraq&m=139905202427693&w=2http://marc.info/?l=bugtraq&m=139905243827825&w=2http://marc.info/?l=bugtraq&m=139905295427946&w=2http://marc.info/?l=bugtraq&m=139905351928096&w=2http://marc.info/?l=bugtraq&m=139905405728262&w=2http://marc.info/?l=bugtraq&m=139905458328378&w=2http://marc.info/?l=bugtraq&m=139905653828999&w=2http://marc.info/?l=bugtraq&m=139905868529690&w=2http://marc.info/?l=bugtraq&m=140015787404650&w=2http://marc.info/?l=bugtraq&m=140075368411126&w=2http://marc.info/?l=bugtraq&m=140724451518351&w=2http://marc.info/?l=bugtraq&m=140752315422991&w=2http://marc.info/?l=bugtraq&m=141287864628122&w=2http://marc.info/?l=bugtraq&m=142660345230545&w=2http://public.support.unisys.com/common/public/vulnerability/NVD_Detail_Rpt.aspx?ID=1http://public.support.unisys.com/common/public/vulnerability/NVD_Detail_Rpt.aspx?ID=3http://rhn.redhat.com/errata/RHSA-2014-0376.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0377.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0378.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0396.htmlhttp://seclists.org/fulldisclosure/2014/Apr/109http://seclists.org/fulldisclosure/2014/Apr/173http://seclists.org/fulldisclosure/2014/Apr/190http://seclists.org/fulldisclosure/2014/Apr/90http://seclists.org/fulldisclosure/2014/Apr/91http://seclists.org/fulldisclosure/2014/Dec/23http://secunia.com/advisories/57347http://secunia.com/advisories/57483http://secunia.com/advisories/57721http://secunia.com/advisories/57836http://secunia.com/advisories/57966http://secunia.com/advisories/57968http://secunia.com/advisories/59139http://secunia.com/advisories/59243http://secunia.com/advisories/59347http://support.citrix.com/article/CTX140605http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140409-heartbleedhttp://www-01.ibm.com/support/docview.wss?uid=isg400001841http://www-01.ibm.com/support/docview.wss?uid=isg400001843http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004661http://www-01.ibm.com/support/docview.wss?uid=swg21670161http://www.apcmedia.com/salestools/SJHN-7RKGNM/SJHN-7RKGNM_R4_EN.pdfhttp://www.blackberry.com/btsc/KB35882http://www.debian.org/security/2014/dsa-2896http://www.exploit-db.com/exploits/32745http://www.exploit-db.com/exploits/32764http://www.f-secure.com/en/web/labs_global/fsc-2014-1http://www.getchef.com/blog/2014/04/09/chef-server-11-0-12-release/http://www.getchef.com/blog/2014/04/09/chef-server-heartbleed-cve-2014-0160-releases/http://www.getchef.com/blog/2014/04/09/enterprise-chef-1-4-9-release/http://www.getchef.com/blog/2014/04/09/enterprise-chef-11-1-3-release/http://www.innominate.com/data/downloads/manuals/mdm_1.5.2.1_Release_Notes.pdfhttp://www.kb.cert.org/vuls/id/720951http://www.kerio.com/support/kerio-control/release-historyhttp://www.mandriva.com/security/advisories?name=MDVSA-2015:062http://www.openssl.org/news/secadv_20140407.txthttp://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.htmlhttp://www.oracle.com/technetwork/topics/security/opensslheartbleedcve-2014-0160-2188454.htmlhttp://www.securityfocus.com/archive/1/534161/100/0/threadedhttp://www.securityfocus.com/bid/66690http://www.securitytracker.com/id/1030026http://www.securitytracker.com/id/1030074http://www.securitytracker.com/id/1030077http://www.securitytracker.com/id/1030078
+ 157 more references
2014-04-07
Published
2022-05-04
Added to CISA KEV
Exploited in the wild