cbcvebase.
CVE-2014-0160
published 2014-04-07

CVE-2014-0160: The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to…

PriorityP190high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2022-05-25
Exploited in the wild
EPSS
100.00%
100.0th percentile
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.

Affected

125 ranges· showing 25
VendorProductVersion rangeFixed in
apachetomcat
broadcomsymantec_messaging_gateway
broadcomsymantec_messaging_gateway
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
ciscoasa
ciscotelepresence_system_mxp_series
ciscotelepresence_tc_and_te
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianopenssl< openssl 1.0.1g-1 (bookworm)openssl 1.0.1g-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
filezilla-projectfilezilla_server< 0.9.440.9.44
hpintegrated_lights-out_2_firmware<= 2.23
hpintegrated_lights-out_2_firmware
hpintegrated_lights-out_2_firmware
hpintegrated_lights-out_2_firmware
hpintegrated_lights-out_2_firmware
hpintegrated_lights-out_2_firmware
hpintegrated_lights-out_2_firmware
hpintegrated_lights-out_2_firmware
hpintegrated_lights-out_2_firmware

Detection & IOCsextracted from sources · hover to see the quote

otherPalo Alto Networks IPS signature 40039
otherPalo Alto Networks IPS signature 36420
otherPalo Alto Networks IPS signature 36419
otherPalo Alto Networks IPS signature 36418
otherPalo Alto Networks IPS signature 36416
snort
1059406 SSL OpenSSL TLS DTLS Heartbeat Information Disclosure -1 (CVE-2014-0160, Heartbleed)
snort
1059407 SSL OpenSSL TLS DTLS Heartbeat Information Disclosure -2 (CVE-2014-0160, Heartbleed)
  • Monitor SSL/TLS traffic for malformed or oversized heartbeat packets — each exploit request can leak up to 64KB of server memory per request, which may appear as anomalously large TLS heartbeat responses.
  • Watch for VPN authentication events following Heartbleed probe activity — attackers in the CHS breach used credentials harvested via Heartbleed to authenticate to VPN and move laterally.
  • ·Crafted TLS heartbeat traffic from CVE-2014-0160 vulnerability-assessment tools can also trigger denial-of-service conditions in unrelated products (e.g., IBM WebSphere Application Server), potentially causing false-positive attribution during scanning.
  • ·Network-based IPS signatures detect exploit attempts but are not a substitute for patching; unpatched systems may remain exploitable even in environments with IPS deployed.

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vulncheck7.5HIGH
cisa7.5HIGH
vendor_apache7.5HIGH
vendor_cisco7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu1.9LOW
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.