PT-2014-9091 · Openssl+14 · Openssl+15

Published

1970-01-01

·

Updated

2026-03-10

·

CVE-2014-0224

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions OpenSSL versions prior to 0.9.8za OpenSSL versions prior to 1.0.0m OpenSSL versions prior to 1.0.1h
Description The issue exists due to incorrect restriction of ChangeCipherSpec message processing in OpenSSL, allowing a man-in-the-middle attacker to trigger the use of a zero-length master key in certain OpenSSL-to-OpenSSL communications. This can lead to session hijacking or obtaining sensitive information via a crafted TLS handshake, also known as the "CCS Injection" vulnerability. The estimated number of potentially affected devices worldwide is not specified. There is no information about real-world incidents where this issue was exploited.
Recommendations For OpenSSL versions prior to 0.9.8za, update to version 0.9.8za or later. For OpenSSL versions prior to 1.0.0m, update to version 1.0.0m or later. For OpenSSL versions prior to 1.0.1h, update to version 1.0.1h or later. As a temporary workaround, consider restricting the use of vulnerable OpenSSL components until a patch is available. Avoid using the ChangeCipherSpec message in affected API endpoints until the issue is resolved.

Exploit

Fix

DoS

NULL Pointer Dereference

Inadequate Encryption Strength

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2014-1734
ALT-PU-2014-2376
ALT-PU-2016-1086
BDU:2015-00125
BDU:2015-00126
BDU:2015-00127
BDU:2015-00128
BDU:2015-04312
BDU:2015-04313
BDU:2015-05844
BDU:2015-05845
BDU:2015-05846
BDU:2015-05847
BDU:2015-05848
BDU:2015-05849
BDU:2015-05850
BDU:2015-05851
BDU:2015-05852
BDU:2015-05853
BDU:2015-05854
BDU:2015-05855
BDU:2015-07477
BDU:2015-07482
BDU:2015-07483
BDU:2015-07485
BDU:2015-09698
CESA-2014_0625
CESA-2014_0626
CVE-2014-0224
DLA-0003-1
DLA-0008-1
DSA-2950-1
ELSA-2014-0625
ELSA-2014-0626
ELSA-2014-0679
ELSA-2014-0680
HPSBUX03046
MGASA-2014-0255
MYSQLLOGINENUMERATIONCHECK
OPENSUSE-SU-2014_0764-1
OPENSUSE-SU-2014_0765-1
OPENSUSE-SU-2016_0640-1
OPENSUSE-SU-2024:10020-1
OPENSUSE-SU-2024:10271-1
OPENSUSE-SU-2024:10529-1
OPENSUSE-SU-2024:11127-1
RHSA-2014:0624
RHSA-2014:0625
RHSA-2014:0626
RHSA-2014:0627
RHSA-2014:0628
RHSA-2014:0629
RHSA-2014:0679
RHSA-2014:0680
RHSA-2014_0624
RHSA-2014_0625
RHSA-2014_0626
RHSA-2014_0679
RHSA-2014_0680
SUSE-FU-2022:0445-1
SUSE-RU-2015:0769-1
SUSE-SU-2015:0182-2
SUSE-SU-2015:0305-1
SUSE-SU-2015:0543-1
SUSE-SU-2015:0545-1
SUSE-SU-2015:0545-2
SUSE-SU-2015:0546-1
SUSE-SU-2015:0578-1
SUSE-SU-2015:0620-1
SUSE-SU-2015:0743-1
SUSE-SU-2015:0946-1
SUSE-SU-2015:1177-1
SUSE-SU-2015:1182-1
SUSE-SU-2015:1182-2
SUSE-SU-2015:1183-1
SUSE-SU-2015:1184-1
SUSE-SU-2015:1184-2
SUSE-SU-2015:1185-1
SUSE-SU-2015_0305-1
SUSE-SU-2019:14246-1
SUSE-SU-2019_14246-1
SUSE-SU-403
USN-2232-1
USN-2232-2
USN-2232-3

Affected Products

Alt Linux
Centos
Check Point Gaia
Cisco Ios
Cisco Ios Xr
Hp-Ux
Huawei Vrp
Ibm Aix
Junos
Mariadb Server
Openssl
Red Hat
Suse
Ubuntu
Vmware Vcenter
Virtualbox