Umbra Wiki cve cve/CVE-2014-0160
Back to wiki

CVE-2014-0160 — OpenSSL Information Disclosure Vulnerability

provenance: imported · CVE: CVE-2014-0160

CVE-2014-0160: OpenSSL Information Disclosure Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project OpenSSL
Product OpenSSL
Date added 2022-05-04
Due date 2022-05-25
Ransomware campaign use Unknown

Description

The TLS and DTLS implementations in OpenSSL do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information.

Required action (CISA)

Apply updates per vendor instructions.

Notes

https://nvd.nist.gov/vuln/detail/CVE-2014-0160

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2014-0160
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog