cbcvebase.
CVE-2014-3470
published 2014-06-05

CVE-2014-3470: The ssl3_send_client_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h, when an anonymous ECDH cipher…

PriorityP339medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
85.78%
99.7th percentile
The ssl3_send_client_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h, when an anonymous ECDH cipher suite is used, allows remote attackers to cause a denial of service (NULL pointer dereference and client crash) by triggering a NULL certificate value.

Affected

24 ranges
VendorProductVersion rangeFixed in
ciscoproducts
debianopenssl< openssl 1.0.1h-1 (bookworm)openssl 1.0.1h-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
mariadbmariadb>= 10.0.0 < 10.0.1310.0.13
opensslopenssl< 0.9.8za0.9.8za
opensslopenssl>= 0 < 1.0.1h-11.0.1h-1
opensslopenssl>= 0 < 1.0.1h-11.0.1h-1
opensslopenssl>= 0 < 1.0.1h-11.0.1h-1
opensslopenssl>= 0 < 1.0.1h-11.0.1h-1
opensslopenssl>= 0 < 1.0.1f-1ubuntu2.31.0.1f-1ubuntu2.3
opensslopenssl>= 0 < 1.0.1f-1ubuntu2.41.0.1f-1ubuntu2.4
opensslopenssl>= 0 < 1.0.1f-1ubuntu2.21.0.1f-1ubuntu2.2
opensslopenssl>= 1.0.0 < 1.0.0m1.0.0m
opensslopenssl>= 1.0.1 < 1.0.1h1.0.1h
opensuseleap
opensuseopensuse
redhatenterprise_linux
redhatenterprise_linux
redhatstorage
suselinux_enterprise_desktop
suselinux_enterprise_server
suselinux_enterprise_software_development_kit
suselinux_enterprise_workstation_extension

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability is triggered when an anonymous ECDH cipher suite is used during TLS handshake; detect TLS ClientKeyExchange messages using anonymous ECDH cipher suites (e.g., AECDH-* cipher suite negotiation) as a potential attack vector
  • The vulnerable code path is in the function ssl3_send_client_key_exchange within s3_clnt.c in OpenSSL; binary/process-level detection should look for vulnerable OpenSSL versions (before 0.9.8za, before 1.0.0m, before 1.0.1h) executing this code path
  • Affected Ubuntu releases include 12.04 LTS, 13.10, and 14.04 LTS; scope detection/patching efforts to these platforms
  • Debian fix was introduced in OpenSSL package version 1.0.1h-1; systems running earlier package versions are vulnerable and should be flagged
  • ·The vulnerability only manifests when an anonymous ECDH (AECDH) cipher suite is negotiated; deployments that do not enable anonymous ECDH cipher suites are not affected
  • ·Impact is client-side only (client crash/DoS); the server is not directly affected — detection and mitigation should focus on client-side OpenSSL usage
  • ·Debian scopes this vulnerability as 'local' in its tracker, which may affect prioritization in some environments

CVSS provenance

nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv6.8MEDIUM
vendor_cisco10.0CRITICAL
vendor_ubuntu6.8MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.