CVE-2014-0160
OpenSSL Information Disclosure Vulnerability
Description
CVE-2014-0160, widely known as the Heartbleed vulnerability, is a critical information disclosure flaw in the OpenSSL cryptographic library. The vulnerability resides in the TLS and DTLS Heartbeat Extension implementation, where improper bounds checking allows a remote attacker to read up to 64 kilobytes of server memory per request, potentially exposing private encryption keys, user credentials, session tokens, and other sensitive data. Heartbleed affects OpenSSL versions 1.0.1 through 1.0.1f, impacting millions of web servers, network devices, and applications worldwide. CISA has added CVE-2014-0160 to the Known Exploited Vulnerabilities catalog with a remediation deadline of May 25, 2022, and the EPSS percentile of approximately 99.997% confirms it is one of the most exploited vulnerabilities in history.
KEV Information
CVSS Score
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NOpen in CalculatorAffected Products
| Vendor | Product | Version |
|---|---|---|
| openssl | openssl | >= 1.0.1, < 1.0.1g |
| filezilla-project | filezilla server | < 0.9.44 |
| siemens | application processing engine firmware | 2.0 |
| siemens | cp 1543-1 firmware | 1.1 |
| siemens | simatic s7-1500 firmware | 1.5 |
| siemens | simatic s7-1500t firmware | 1.5 |
| siemens | elan-8.2 | < 8.3.3 |
| siemens | wincc open architecture | 3.12 |
| intellian | v100 firmware | 1.20; 1.21; 1.24 |
| intellian | v60 firmware | 1.15; 1.25 |
| mitel | micollab | 6.0; 7.0; 7.1; 7.2; 7.3; 7.3.0.104 |
| mitel | mivoice | 1.1.2.5; 1.1.3.3; 1.2.0.11; 1.3.2.2; 1.4.0.102 |
| opensuse | opensuse | 12.3; 13.1 |
| canonical | ubuntu linux | 12.04; 12.10; 13.10 |
| fedoraproject | fedora | 19; 20 |
| redhat | gluster storage | 2.1 |
| redhat | storage | 2.1 |
| redhat | virtualization | 6.0 |
| redhat | enterprise linux desktop | 6.0 |
| redhat | enterprise linux server | 6.0 |
Multiple CVSS Assessments
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
References
- http://advisories.mageia.org/MGASA-2014-0165.html(Third Party Advisory)
- http://blog.fox-it.com/2014/04/08/openssl-heartbleed-bug-live-blog/(Issue Tracking, Third Party Advisory)
- http://cogentdatahub.com/ReleaseNotes.html(Release Notes)
- http://download.schneider-electric.com/files?p_Doc_Ref=SEVD%202014-119-01(Broken Link)
- http://git.openssl.org/gitweb/?p=openssl.git%3Ba=commit%3Bh=96db9023b881d7cd9f379b0c154650d6c108e9a3(Broken Link)
- http://heartbleed.com/(Third Party Advisory)
- http://lists.fedoraproject.org/pipermail/package-announce/2014-April/131221.html(Broken Link, Third Party Advisory)
- http://lists.fedoraproject.org/pipermail/package-announce/2014-April/131291.html(Broken Link, Third Party Advisory)
- http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136473.html(Mailing List, Third Party Advisory)
- http://lists.opensuse.org/opensuse-security-announce/2014-04/msg00004.html(Mailing List, Third Party Advisory)
- http://lists.opensuse.org/opensuse-security-announce/2014-04/msg00005.html(Mailing List, Third Party Advisory)
- http://lists.opensuse.org/opensuse-updates/2014-04/msg00061.html(Mailing List, Third Party Advisory)
- http://marc.info/?l=bugtraq&m=139722163017074&w=2(Mailing List, Third Party Advisory)
- http://marc.info/?l=bugtraq&m=139757726426985&w=2(Mailing List, Third Party Advisory)
- http://marc.info/?l=bugtraq&m=139757819327350&w=2(Mailing List, Third Party Advisory)
- http://marc.info/?l=bugtraq&m=139757919027752&w=2(Mailing List, Third Party Advisory)
- http://marc.info/?l=bugtraq&m=139758572430452&w=2(Mailing List, Third Party Advisory)
- http://marc.info/?l=bugtraq&m=139765756720506&w=2(Mailing List, Third Party Advisory)
- http://marc.info/?l=bugtraq&m=139774054614965&w=2(Mailing List, Third Party Advisory)
- http://marc.info/?l=bugtraq&m=139774703817488&w=2(Mailing List, Third Party Advisory)
- http://marc.info/?l=bugtraq&m=139808058921905&w=2(Mailing List, Third Party Advisory)
- http://marc.info/?l=bugtraq&m=139817685517037&w=2(Mailing List, Third Party Advisory)
- http://marc.info/?l=bugtraq&m=139817727317190&w=2(Mailing List, Third Party Advisory)
- http://marc.info/?l=bugtraq&m=139817782017443&w=2(Mailing List, Third Party Advisory)
- http://marc.info/?l=bugtraq&m=139824923705461&w=2(Mailing List, Third Party Advisory)
- http://marc.info/?l=bugtraq&m=139824993005633&w=2(Mailing List, Third Party Advisory)
- http://marc.info/?l=bugtraq&m=139833395230364&w=2(Mailing List, Third Party Advisory)
- http://marc.info/?l=bugtraq&m=139835815211508&w=2(Mailing List, Third Party Advisory)
- http://marc.info/?l=bugtraq&m=139835844111589&w=2(Mailing List, Third Party Advisory)
- http://marc.info/?l=bugtraq&m=139836085512508&w=2(Mailing List, Third Party Advisory)
- http://marc.info/?l=bugtraq&m=139842151128341&w=2(Mailing List, Third Party Advisory)
- http://marc.info/?l=bugtraq&m=139843768401936&w=2(Mailing List, Third Party Advisory)
- http://marc.info/?l=bugtraq&m=139869720529462&w=2(Mailing List, Third Party Advisory)
- http://marc.info/?l=bugtraq&m=139869891830365&w=2(Mailing List, Third Party Advisory)
- http://marc.info/?l=bugtraq&m=139889113431619&w=2(Mailing List, Third Party Advisory)
- http://marc.info/?l=bugtraq&m=139889295732144&w=2(Mailing List, Third Party Advisory)
- http://marc.info/?l=bugtraq&m=139905202427693&w=2(Mailing List, Third Party Advisory)
- http://marc.info/?l=bugtraq&m=139905243827825&w=2(Mailing List, Third Party Advisory)
- http://marc.info/?l=bugtraq&m=139905295427946&w=2(Mailing List, Third Party Advisory)
- http://marc.info/?l=bugtraq&m=139905351928096&w=2(Mailing List, Third Party Advisory)
- http://marc.info/?l=bugtraq&m=139905405728262&w=2(Mailing List, Third Party Advisory)
- http://marc.info/?l=bugtraq&m=139905458328378&w=2(Mailing List, Third Party Advisory)
- http://marc.info/?l=bugtraq&m=139905653828999&w=2(Mailing List, Third Party Advisory)
- http://marc.info/?l=bugtraq&m=139905868529690&w=2(Mailing List, Third Party Advisory)
- http://marc.info/?l=bugtraq&m=140015787404650&w=2(Mailing List, Third Party Advisory)
- http://marc.info/?l=bugtraq&m=140075368411126&w=2(Mailing List, Third Party Advisory)
- http://marc.info/?l=bugtraq&m=140724451518351&w=2(Mailing List, Third Party Advisory)
- http://marc.info/?l=bugtraq&m=140752315422991&w=2(Mailing List, Third Party Advisory)
- http://marc.info/?l=bugtraq&m=141287864628122&w=2(Mailing List, Third Party Advisory)
- http://marc.info/?l=bugtraq&m=142660345230545&w=2(Mailing List, Third Party Advisory)
- http://public.support.unisys.com/common/public/vulnerability/NVD_Detail_Rpt.aspx?ID=1(Third Party Advisory)
- http://public.support.unisys.com/common/public/vulnerability/NVD_Detail_Rpt.aspx?ID=3(Permissions Required, Third Party Advisory)
- http://rhn.redhat.com/errata/RHSA-2014-0376.html(Third Party Advisory)
- http://rhn.redhat.com/errata/RHSA-2014-0377.html(Third Party Advisory)
- http://rhn.redhat.com/errata/RHSA-2014-0378.html(Third Party Advisory)
- http://rhn.redhat.com/errata/RHSA-2014-0396.html(Third Party Advisory)
- http://seclists.org/fulldisclosure/2014/Apr/109(Mailing List, Third Party Advisory)
- http://seclists.org/fulldisclosure/2014/Apr/173(Mailing List, Third Party Advisory)
- http://seclists.org/fulldisclosure/2014/Apr/190(Mailing List, Third Party Advisory)
- http://seclists.org/fulldisclosure/2014/Apr/90(Mailing List, Third Party Advisory)
- http://seclists.org/fulldisclosure/2014/Apr/91(Mailing List, Third Party Advisory)
- http://seclists.org/fulldisclosure/2014/Dec/23(Mailing List, Third Party Advisory)
- http://secunia.com/advisories/57347(Broken Link, Third Party Advisory)
- http://secunia.com/advisories/57483(Broken Link, Third Party Advisory)
- http://secunia.com/advisories/57721(Broken Link, Third Party Advisory)
- http://secunia.com/advisories/57836(Broken Link, Third Party Advisory)
- http://secunia.com/advisories/57966(Broken Link, Third Party Advisory)
- http://secunia.com/advisories/57968(Broken Link, Third Party Advisory)
- http://secunia.com/advisories/59139(Broken Link, Third Party Advisory)
- http://secunia.com/advisories/59243(Broken Link, Third Party Advisory)
- http://secunia.com/advisories/59347(Broken Link, Third Party Advisory)
- http://support.citrix.com/article/CTX140605(Third Party Advisory)
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140409-heartbleed(Third Party Advisory)
- http://www-01.ibm.com/support/docview.wss?uid=isg400001841(Third Party Advisory)
- http://www-01.ibm.com/support/docview.wss?uid=isg400001843(Third Party Advisory)
- http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004661(Third Party Advisory)
- http://www-01.ibm.com/support/docview.wss?uid=swg21670161(Broken Link)
- http://www.apcmedia.com/salestools/SJHN-7RKGNM/SJHN-7RKGNM_R4_EN.pdf(Broken Link, Third Party Advisory)
- http://www.blackberry.com/btsc/KB35882(Broken Link)
- http://www.debian.org/security/2014/dsa-2896(Mailing List, Third Party Advisory)
- http://www.exploit-db.com/exploits/32745(Exploit, Third Party Advisory, VDB Entry)
- http://www.exploit-db.com/exploits/32764(Exploit, Third Party Advisory, VDB Entry)
- http://www.f-secure.com/en/web/labs_global/fsc-2014-1(Broken Link, Third Party Advisory)
- http://www.getchef.com/blog/2014/04/09/chef-server-11-0-12-release/(Release Notes)
- http://www.getchef.com/blog/2014/04/09/chef-server-heartbleed-cve-2014-0160-releases/(Third Party Advisory)
- http://www.getchef.com/blog/2014/04/09/enterprise-chef-1-4-9-release/(Release Notes)
- http://www.getchef.com/blog/2014/04/09/enterprise-chef-11-1-3-release/(Release Notes)
- http://www.innominate.com/data/downloads/manuals/mdm_1.5.2.1_Release_Notes.pdf(Not Applicable)
- http://www.kb.cert.org/vuls/id/720951(Third Party Advisory, US Government Resource)
- http://www.kerio.com/support/kerio-control/release-history(Broken Link, Third Party Advisory)
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:062(Broken Link, Third Party Advisory)
- http://www.openssl.org/news/secadv_20140407.txt(Broken Link, Vendor Advisory)
- http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html(Patch, Third Party Advisory)
- http://www.oracle.com/technetwork/topics/security/opensslheartbleedcve-2014-0160-2188454.html(Patch, Third Party Advisory)
- http://www.securityfocus.com/archive/1/534161/100/0/threaded(Broken Link, Not Applicable, Third Party Advisory, VDB Entry)
- http://www.securityfocus.com/bid/66690(Broken Link, Third Party Advisory, VDB Entry)
- http://www.securitytracker.com/id/1030026(Broken Link, Third Party Advisory, VDB Entry)
- http://www.securitytracker.com/id/1030074(Broken Link, Third Party Advisory, VDB Entry)
- http://www.securitytracker.com/id/1030077(Broken Link, Third Party Advisory, VDB Entry)
- http://www.securitytracker.com/id/1030078(Broken Link, Third Party Advisory, VDB Entry)
- http://www.securitytracker.com/id/1030079(Broken Link, Third Party Advisory, VDB Entry)
- http://www.securitytracker.com/id/1030080(Broken Link, Third Party Advisory, VDB Entry)
- http://www.securitytracker.com/id/1030081(Broken Link, Third Party Advisory, VDB Entry)
- http://www.securitytracker.com/id/1030082(Broken Link, Third Party Advisory, VDB Entry)
- http://www.splunk.com/view/SP-CAAAMB3(Third Party Advisory)
- http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20160512_00(Third Party Advisory)
- http://www.ubuntu.com/usn/USN-2165-1(Third Party Advisory)
- http://www.us-cert.gov/ncas/alerts/TA14-098A(Third Party Advisory, US Government Resource)
- http://www.vmware.com/security/advisories/VMSA-2014-0012.html(Broken Link)
- http://www.websense.com/support/article/kbarticle/Vulnerabilities-resolved-in-TRITON-APX-Version-8-0(Broken Link)
- https://blog.torproject.org/blog/openssl-bug-cve-2014-0160(Issue Tracking)
- https://bugzilla.redhat.com/show_bug.cgi?id=1084875(Issue Tracking, Third Party Advisory)
- https://cert-portal.siemens.com/productcert/pdf/ssa-635659.pdf(Third Party Advisory)
- https://code.google.com/p/mod-spdy/issues/detail?id=85(Issue Tracking)
- https://filezilla-project.org/versions.php?type=server(Release Notes)
- https://gist.github.com/chapmajs/10473815(Exploit)
- https://h20566.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?spf_p.tpst=kbDocDisplay&spf_p.prp_kbDocDisplay=wsrp-navigationalState%3DdocId%253Demr_na-c04260637-4%257CdocLocale%253Den_US%257CcalledBy%253DSearch_Result&javax.portlet.begCacheTok=com.vignette.cachetoken&javax.portlet.endCacheTok=com.vignette.cachetoken(Broken Link)
- https://lists.apache.org/thread.html/ba661b0edd913b39ff129a32d855620dd861883ade05fd88a8ce517d%40%3Cdev.tomcat.apache.org%3E(Mailing List, Patch, Third Party Advisory)
- https://lists.apache.org/thread.html/f8e0814e11c7f21f42224b6de111cb3f5e5ab5c15b78924c516d4ec2%40%3Cdev.tomcat.apache.org%3E(Mailing List, Patch, Third Party Advisory)
- https://lists.apache.org/thread.html/re3b72cbb13e1dfe85c4a06959a3b6ca6d939b407ecca80db12b54220%40%3Cdev.tomcat.apache.org%3E(Mailing List, Patch, Third Party Advisory)
- https://lists.apache.org/thread.html/rf8e8c091182b45daa50d3557cad9b10bb4198e3f08cf8f1c66a1b08d%40%3Cdev.tomcat.apache.org%3E(Mailing List, Patch, Third Party Advisory)
- https://lists.balabit.hu/pipermail/syslog-ng-announce/2014-April/000184.html(Mailing List, Third Party Advisory)
- https://sku11army.blogspot.com/2020/01/heartbleed-hearts-continue-to-bleed.html(Exploit, Permissions Required, Third Party Advisory)
- https://support.f5.com/kb/en-us/solutions/public/15000/100/sol15159.html(Third Party Advisory)
- https://support.f5.com/kb/en-us/solutions/public/15000/100/sol15159.html?sr=36517217(Third Party Advisory)
- https://www.cert.fi/en/reports/2014/vulnerability788210.html(Not Applicable, Third Party Advisory)
- https://www.mitel.com/en-ca/support/security-advisories/mitel-product-security-advisory-17-0008(Third Party Advisory)
- https://yunus-shn.medium.com/ricon-industrial-cellular-router-heartbleed-attack-2634221c02bd(Broken Link, Exploit, Third Party Advisory)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2014-0160(US Government Resource)
Weakness Type
CWE-125: Out-of-bounds Read
The Heartbleed vulnerability in OpenSSL is an out-of-bounds read that occurs when the TLS Heartbeat Extension handler fails to validate the length field in a heartbeat request message. The OpenSSL implementation reads memory beyond the intended buffer boundary, returning up to 64 KB of adjacent server process memory to the attacker, which can contain cryptographic keys, passwords, and other sensitive information.
Learn more: CWE-125 — Out-of-bounds Read
Impact Analysis
CVE-2014-0160 is remotely exploitable over the network without any authentication or user interaction, making it trivially easy to exploit at scale. The vulnerability only requires sending a malformed Heartbeat request to any TLS-enabled service running a vulnerable version of OpenSSL. Confidentiality (Critical): The primary impact is massive information disclosure, as attackers can repeatedly read 64 KB chunks of server memory, potentially extracting TLS private keys, user passwords, session cookies, and other secrets processed by the server. Integrity: While Heartbleed itself is a read-only vulnerability, stolen private keys enable man-in-the-middle attacks that compromise the integrity of all encrypted communications. Availability: The vulnerability does not directly cause denial of service, but the remediation process (key rotation, certificate reissuance, forced password resets) can be highly disruptive. The EPSS percentile of approximately 99.997% places Heartbleed at the absolute peak of exploitation probability, and its impact on global internet security has been historically unprecedented.
Exploit Maturity
CISA has confirmed active exploitation of CVE-2014-0160 in the wild by including it in the Known Exploited Vulnerabilities catalog with a remediation deadline of May 25, 2022. The EPSS percentile of approximately 99.997% indicates near-universal exploitation activity, making Heartbleed one of the single most exploited vulnerabilities in internet history. Public exploit tools have been freely available since the day of disclosure, and exploitation requires no specialized skills or custom tooling. Automated scanning tools can identify and exploit vulnerable servers in seconds, and the vulnerability has been actively exploited by both state-sponsored actors and criminal groups since April 2014.
Remediation
-
Upgrade OpenSSL immediately to version 1.0.1g or later, or apply the Heartbleed patch to your existing OpenSSL installation. As directed by CISA: "Apply updates per vendor instructions." Verify the OpenSSL version on all servers, network devices, and applications that use TLS.
-
Revoke and reissue all TLS/SSL certificates on servers that ran vulnerable OpenSSL versions, as the private keys may have been compromised. Generate new key pairs before requesting replacement certificates, and ensure old certificates are added to Certificate Revocation Lists (CRLs).
-
Force password resets for all users whose credentials may have been transmitted through or stored in memory of vulnerable servers. This includes web application passwords, API tokens, session identifiers, and any other authentication material that could have been exposed through the memory leak.
-
Audit all systems and applications that link against OpenSSL to ensure comprehensive patching. This includes web servers (Apache, Nginx), VPN appliances, email servers, database connectors, and any embedded devices or IoT systems that use OpenSSL for TLS communication.
-
Implement monitoring for Heartbleed exploitation attempts by deploying IDS/IPS signatures that detect malformed Heartbeat requests. Review server logs and network traffic captures for evidence of past exploitation, and consider engaging an incident response team if exploitation is suspected to have occurred before patching.
Technical Details
CVE-2014-0160 exploits a missing bounds check in OpenSSL's implementation of the TLS Heartbeat Extension (RFC 6520), specifically in the dtls1_process_heartbeat() and tls1_process_heartbeat() functions. When processing a Heartbeat request, the code reads the user-specified payload length from the request but fails to verify that the actual payload matches the declared length, then uses memcpy() to copy the declared number of bytes from the received message buffer into the response. An attacker sends a Heartbeat request with a small payload (as little as 1 byte) but declares a payload length of up to 65,535 bytes, causing OpenSSL to read beyond the message buffer into adjacent process memory and return the contents to the attacker. This out-of-bounds read occurs in the context of the server's TLS process, which typically holds highly sensitive data including private keys, decrypted application data, and user credentials in its heap memory.
Frequently Asked Questions
Is CVE-2014-0160 being actively exploited?
Yes, CVE-2014-0160 (Heartbleed) has been actively exploited since its public disclosure in April 2014. CISA has included it in the Known Exploited Vulnerabilities catalog. The EPSS percentile of approximately 99.997% makes it one of the most exploited vulnerabilities in internet history, with automated tools enabling trivial exploitation.
What products are affected by CVE-2014-0160?
CVE-2014-0160 affects OpenSSL versions 1.0.1 through 1.0.1f. This impacts a vast range of products including web servers (Apache, Nginx), VPN appliances, email servers, network devices, and any application that links against a vulnerable OpenSSL version for TLS support.
How do I fix CVE-2014-0160?
Upgrade OpenSSL to version 1.0.1g or later on all affected systems. After patching, revoke and reissue all TLS certificates as private keys may have been compromised, generate new key pairs, and force password resets for users whose credentials may have been exposed.
How severe is CVE-2014-0160?
CVE-2014-0160 is one of the most severe vulnerabilities ever discovered, with an EPSS percentile of approximately 99.997%. Heartbleed allows unauthenticated remote attackers to silently extract sensitive data from server memory, including private encryption keys and user credentials, with no trace in standard server logs.
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.