cbcvebase.
CVE-2014-3566
published 2014-10-15

CVE-2014-3566: The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle…

PriorityP343low3.4CVSS 3.1
AVNACHPRNUIRSCCLINAN
EXPLOIT
EPSS
100.00%
100.0th percentile
The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.

Affected

337 ranges· showing 25
VendorProductVersion rangeFixed in
applemac_os_x<= 10.10.1
appleos_x_server_v4.1
appleos_x_yosemite_v10.10.2_and_security_update_2015-001
applexcode
apsispound>= 0 < 2.6-62.6-6
apsispound>= 0 < 2.6-62.6-6
apsispound>= 0 < 2.6-62.6-6
citrixnetscaler_adc_gateway
clouderacloudera_manager
clouderacloudera_manager
clouderacloudera_manager
clouderacloudera_manager
clouderacloudera_manager
clouderacloudera_manager
clouderanavigator
clouderanavigator
clouderanavigator
clouderanavigator
clouderanavigator
clouderanavigator
debianbouncycastle< erlang 1:17.3-dfsg-3 (bookworm)erlang 1:17.3-dfsg-3 (bookworm)
debiandebian_linux
debiandebian_linux
debianepiphany-browser< erlang 1:17.3-dfsg-3 (bookworm)erlang 1:17.3-dfsg-3 (bookworm)
debianerlang< erlang 1:17.3-dfsg-3 (bookworm)erlang 1:17.3-dfsg-3 (bookworm)

Detection & IOCsextracted from sources · hover to see the quote

otherSnort SID 32204
otherSnort SID 32205
otherCisco IPS signature 4743-0
otherPalo Alto IPS signature ID 36815 – SSLv3 Found in Server Response
otherTrend Micro rule 1130118 – SSL OpenSSL SSLv3 POODLE Padding Brute Force (CVE-2014-3566)
  • Alert on any SSLv3 connection negotiation in server responses; presence of SSLv3 indicates potential POODLE attack surface regardless of whether an active attack is underway.
  • Detect SSLv3 CBC padding oracle exploitation by monitoring for modified/replayed SSL packets with anomalous padding bytes targeting the same session.
  • Monitor for TLS downgrade handshakes where a client falls back from TLS to SSLv3; this forced downgrade is the prerequisite for POODLE exploitation.
  • Focus detection on port 443 traffic for SSLv3 sessions; POODLE exploitation is most prevalent on this port.
  • Hits on Palo Alto IPS signature 36815 (SSLv3 Found in Server Response) do not confirm an active attack but indicate any such session is vulnerable to POODLE and should be treated as potentially compromised.
  • ·The POODLE attack requires the attacker to already be in the network path (man-in-the-middle); remote unauthenticated exploitation without network interception is not possible.
  • ·CVE-2014-8730 (F5 BIG-IP variant) is scoped only to the F5 implementation; other vulnerable TLS 1.x implementations with improper CBC padding checks should receive separate CVE IDs and are not covered by this identifier.
  • ·SSLv3 IPS signature hits indicate exposure but not confirmed exploitation; all SSLv3 sessions should be treated as potentially compromised.

CVSS provenance

nvdv3.13.4LOWCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv3.4LOW
vendor_cisco3.4LOW
vendor_debian3.4LOW
vendor_redhat3.4LOW
vendor_ubuntu3.4LOW
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.