Man-in-the-Middle attack in OpenSSL - CVE-2014-0224

 

Man-in-the-Middle attack in OpenSSL - CVE-2014-0224

Published: November 30, -0001 / Updated: September 14, 2018


Vulnerability identifier: #VU2950
CSH Severity: Medium
CVSS v4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-0224
CWE-ID: CWE-310
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to decrypt encrypted connections.

The vulnerability exists due to an error in OpenSSL. A remote attacker with ability to intercept network traffic can decrypt SSL connection and gain access to sensitive data.

Affected software

OpenSSL
Amazon Linux AMI
Gentoo Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Fedora
Red Hat Enterprise Linux EUS Compute Node
SUSE Linux
Opensuse
Ubuntu
Slackware Linux
XIV Storage System Gen2
HPE OneView
Operations Analytics
Cloud Service Automation (CSA)
HP IT Executive Scorecard
Server Automation
FlashSystem 840 9840-AE1 & 9843-AE1
Integrity SD2 CB900s i4 & i2
Command View for Tape Libraries (CVTL)
3PAR Service Processors
FlashSystem 710 & 810 Machine Type 9830 -AS1 & -AE1
TMS RAMSAN 710 & 810 Machine Type 9833 -AS1 & -AE1
TMS RAMSAN 720 and 820 machine type 9834 -AS2 & AE2
IBM FlashSystem 720 and 820 Machine Type 9831 –AS2 and -AE2
CloudSystem Foundation
CloudSystem Enterprise
CloudSystem Chargeback
IDOL Speech Software
IDOL Image Server
IDOL Software
XIV Gen3
TS2900 Tape Autoloader
openssl (Ubuntu package)
mingw-openssl
HP Database and Middleware Automation
HP Onboard Administrator
HPE Service Manager
IBM BladeCenter Advanced Management Module
BladeSystem c-Class Virtual Connect Firmware
SAN Volume Controller and Storwize Family
HP Smart Update Manager
HP AssetManager
IBM Storwize V3500
IBM Storwize V7000
IBM Storwize V5000
IBM Storwize V3700

How to mitigate CVE-2014-0224

Update to version 0.9.8za, 1.0.0m or 1.0.1h.

openssl (Ubuntu package) - update to 0.9.8k-7ubuntu8.21
mingw-openssl - addressed in versions 1.0.1j-1.el7, 1.0.1j-1.fc21
FlashSystem 840 9840-AE1 & 9843-AE1 - update to 1.1.2.2
Integrity SD2 CB900s i4 & i2 - update to 3.7.98
Command View for Tape Libraries (CVTL) - update to 3.8.00
IBM BladeCenter Advanced Management Module - update to 3.66F
3PAR Service Processors - addressed in versions 4.1.0.GA-97.P011, 4.2.0.GA-29.P003, 4.3.0.GA-17.P001
HP Onboard Administrator - update to 4.22
BladeSystem c-Class Virtual Connect Firmware - update to 4.30
FlashSystem 710 & 810 Machine Type 9830 -AS1 & -AE1 - update to 5.6.2
TMS RAMSAN 710 & 810 Machine Type 9833 -AS1 & -AE1 - update to 5.6.2
TMS RAMSAN 720 and 820 machine type 9834 -AS2 & AE2 - update to 6.3.2
IBM FlashSystem 720 and 820 Machine Type 9831 –AS2 and -AE2 - update to 6.3.2
HP Smart Update Manager - update to 6.4.1
IBM Storwize V3500 - addressed in versions 7.1.0.10, 7.2.0.7, 7.3.0.3
SAN Volume Controller and Storwize Family - addressed in versions 7.1.0.10, 7.2.0.7, 7.3.0.3
IBM Storwize V7000 - addressed in versions 7.1.0.10, 7.2.0.7, 7.3.0.3
IBM Storwize V5000 - addressed in versions 7.1.0.10, 7.2.0.7, 7.3.0.3
IBM Storwize V3700 - addressed in versions 7.1.0.10, 7.2.0.7, 7.3.0.3
HPE Service Manager - addressed in versions 7.11.720 p22, 9.21.706 P9, 9.34.2003 p2
CloudSystem Foundation - update to 8.1
CloudSystem Enterprise - update to 8.1
HP AssetManager - addressed in versions 9.32.P2, 9.40.P4, 9.41.P1
CloudSystem Chargeback - update to 9.40.P4
IDOL Speech Software - update to 10.7
IDOL Image Server - update to 10.7
IDOL Software - update to 10.7
XIV Gen3 - addressed in versions 11.3.1.c, 11.4.2.a
TS2900 Tape Autoloader - update to 0033

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins