CVE-2014-0224

Published Jun 5, 2014

Last updated 19 days ago

Overview

Description
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive information, via a crafted TLS handshake, aka the "CCS Injection" vulnerability.
Source
secalert@redhat.com
NVD status
Modified
Products
openssl, jboss_enterprise_application_platform, jboss_enterprise_web_platform, jboss_enterprise_web_server, storage, fedora, opensuse, enterprise_linux, filezilla_server, application_processing_engine_firmware, cp1543-1_firmware, s7-1500_firmware, rox_firmware, mariadb, python, node.js

Risk scores

CVSS 3.1

Type
Primary
Base score
7.4
Impact score
5.2
Exploitability score
2.2
Vector string
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Severity
HIGH

CVSS 2.0

Type
Primary
Base score
5.8
Impact score
4.9
Exploitability score
8.6
Vector string
AV:N/AC:M/Au:N/C:P/I:P/A:N

Weaknesses

nvd@nist.gov
CWE-326

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.