Man-in-the-Middle attack in OpenSSL - CVE-2014-0224
Published: November 30, -0001 / Updated: September 14, 2018
Vulnerability identifier: #VU2950
CSH Severity: Medium
CVSS v4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-0224
CWE-ID: CWE-310
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a remote attacker to decrypt encrypted connections.
The vulnerability exists due to an error in OpenSSL. A remote attacker with ability to intercept network traffic can decrypt SSL connection and gain access to sensitive data.
The vulnerability exists due to an error in OpenSSL. A remote attacker with ability to intercept network traffic can decrypt SSL connection and gain access to sensitive data.
Affected software
OpenSSL
Amazon Linux AMI
Gentoo Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Fedora
Red Hat Enterprise Linux EUS Compute Node
SUSE Linux
Opensuse
Ubuntu
Slackware Linux
XIV Storage System Gen2
HPE OneView
Operations Analytics
Cloud Service Automation (CSA)
HP IT Executive Scorecard
Server Automation
FlashSystem 840 9840-AE1 & 9843-AE1
Integrity SD2 CB900s i4 & i2
Command View for Tape Libraries (CVTL)
3PAR Service Processors
FlashSystem 710 & 810 Machine Type 9830 -AS1 & -AE1
TMS RAMSAN 710 & 810 Machine Type 9833 -AS1 & -AE1
TMS RAMSAN 720 and 820 machine type 9834 -AS2 & AE2
IBM FlashSystem 720 and 820 Machine Type 9831 –AS2 and -AE2
CloudSystem Foundation
CloudSystem Enterprise
CloudSystem Chargeback
IDOL Speech Software
IDOL Image Server
IDOL Software
XIV Gen3
TS2900 Tape Autoloader
openssl (Ubuntu package)
mingw-openssl
HP Database and Middleware Automation
HP Onboard Administrator
HPE Service Manager
IBM BladeCenter Advanced Management Module
BladeSystem c-Class Virtual Connect Firmware
SAN Volume Controller and Storwize Family
HP Smart Update Manager
HP AssetManager
IBM Storwize V3500
IBM Storwize V7000
IBM Storwize V5000
IBM Storwize V3700
Amazon Linux AMI
Gentoo Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Fedora
Red Hat Enterprise Linux EUS Compute Node
SUSE Linux
Opensuse
Ubuntu
Slackware Linux
XIV Storage System Gen2
HPE OneView
Operations Analytics
Cloud Service Automation (CSA)
HP IT Executive Scorecard
Server Automation
FlashSystem 840 9840-AE1 & 9843-AE1
Integrity SD2 CB900s i4 & i2
Command View for Tape Libraries (CVTL)
3PAR Service Processors
FlashSystem 710 & 810 Machine Type 9830 -AS1 & -AE1
TMS RAMSAN 710 & 810 Machine Type 9833 -AS1 & -AE1
TMS RAMSAN 720 and 820 machine type 9834 -AS2 & AE2
IBM FlashSystem 720 and 820 Machine Type 9831 –AS2 and -AE2
CloudSystem Foundation
CloudSystem Enterprise
CloudSystem Chargeback
IDOL Speech Software
IDOL Image Server
IDOL Software
XIV Gen3
TS2900 Tape Autoloader
openssl (Ubuntu package)
mingw-openssl
HP Database and Middleware Automation
HP Onboard Administrator
HPE Service Manager
IBM BladeCenter Advanced Management Module
BladeSystem c-Class Virtual Connect Firmware
SAN Volume Controller and Storwize Family
HP Smart Update Manager
HP AssetManager
IBM Storwize V3500
IBM Storwize V7000
IBM Storwize V5000
IBM Storwize V3700
How to mitigate CVE-2014-0224
Update to version 0.9.8za, 1.0.0m or 1.0.1h.
openssl (Ubuntu package) - update to 0.9.8k-7ubuntu8.21
mingw-openssl - addressed in versions 1.0.1j-1.el7, 1.0.1j-1.fc21
FlashSystem 840 9840-AE1 & 9843-AE1 - update to 1.1.2.2
Integrity SD2 CB900s i4 & i2 - update to 3.7.98
Command View for Tape Libraries (CVTL) - update to 3.8.00
IBM BladeCenter Advanced Management Module - update to 3.66F
3PAR Service Processors - addressed in versions 4.1.0.GA-97.P011, 4.2.0.GA-29.P003, 4.3.0.GA-17.P001
HP Onboard Administrator - update to 4.22
BladeSystem c-Class Virtual Connect Firmware - update to 4.30
FlashSystem 710 & 810 Machine Type 9830 -AS1 & -AE1 - update to 5.6.2
TMS RAMSAN 710 & 810 Machine Type 9833 -AS1 & -AE1 - update to 5.6.2
TMS RAMSAN 720 and 820 machine type 9834 -AS2 & AE2 - update to 6.3.2
IBM FlashSystem 720 and 820 Machine Type 9831 –AS2 and -AE2 - update to 6.3.2
HP Smart Update Manager - update to 6.4.1
IBM Storwize V3500 - addressed in versions 7.1.0.10, 7.2.0.7, 7.3.0.3
SAN Volume Controller and Storwize Family - addressed in versions 7.1.0.10, 7.2.0.7, 7.3.0.3
IBM Storwize V7000 - addressed in versions 7.1.0.10, 7.2.0.7, 7.3.0.3
IBM Storwize V5000 - addressed in versions 7.1.0.10, 7.2.0.7, 7.3.0.3
IBM Storwize V3700 - addressed in versions 7.1.0.10, 7.2.0.7, 7.3.0.3
HPE Service Manager - addressed in versions 7.11.720 p22, 9.21.706 P9, 9.34.2003 p2
CloudSystem Foundation - update to 8.1
CloudSystem Enterprise - update to 8.1
HP AssetManager - addressed in versions 9.32.P2, 9.40.P4, 9.41.P1
CloudSystem Chargeback - update to 9.40.P4
IDOL Speech Software - update to 10.7
IDOL Image Server - update to 10.7
IDOL Software - update to 10.7
XIV Gen3 - addressed in versions 11.3.1.c, 11.4.2.a
TS2900 Tape Autoloader - update to 0033
mingw-openssl - addressed in versions 1.0.1j-1.el7, 1.0.1j-1.fc21
FlashSystem 840 9840-AE1 & 9843-AE1 - update to 1.1.2.2
Integrity SD2 CB900s i4 & i2 - update to 3.7.98
Command View for Tape Libraries (CVTL) - update to 3.8.00
IBM BladeCenter Advanced Management Module - update to 3.66F
3PAR Service Processors - addressed in versions 4.1.0.GA-97.P011, 4.2.0.GA-29.P003, 4.3.0.GA-17.P001
HP Onboard Administrator - update to 4.22
BladeSystem c-Class Virtual Connect Firmware - update to 4.30
FlashSystem 710 & 810 Machine Type 9830 -AS1 & -AE1 - update to 5.6.2
TMS RAMSAN 710 & 810 Machine Type 9833 -AS1 & -AE1 - update to 5.6.2
TMS RAMSAN 720 and 820 machine type 9834 -AS2 & AE2 - update to 6.3.2
IBM FlashSystem 720 and 820 Machine Type 9831 –AS2 and -AE2 - update to 6.3.2
HP Smart Update Manager - update to 6.4.1
IBM Storwize V3500 - addressed in versions 7.1.0.10, 7.2.0.7, 7.3.0.3
SAN Volume Controller and Storwize Family - addressed in versions 7.1.0.10, 7.2.0.7, 7.3.0.3
IBM Storwize V7000 - addressed in versions 7.1.0.10, 7.2.0.7, 7.3.0.3
IBM Storwize V5000 - addressed in versions 7.1.0.10, 7.2.0.7, 7.3.0.3
IBM Storwize V3700 - addressed in versions 7.1.0.10, 7.2.0.7, 7.3.0.3
HPE Service Manager - addressed in versions 7.11.720 p22, 9.21.706 P9, 9.34.2003 p2
CloudSystem Foundation - update to 8.1
CloudSystem Enterprise - update to 8.1
HP AssetManager - addressed in versions 9.32.P2, 9.40.P4, 9.41.P1
CloudSystem Chargeback - update to 9.40.P4
IDOL Speech Software - update to 10.7
IDOL Image Server - update to 10.7
IDOL Software - update to 10.7
XIV Gen3 - addressed in versions 11.3.1.c, 11.4.2.a
TS2900 Tape Autoloader - update to 0033
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Amazon Linux AMI update for openssl098e
- Amazon Linux AMI update for openssl097a
- Multiple vulnerabilities in OpenSSL
- Ubuntu update for OpenSSL
- Ubuntu update for OpenSSL
- Ubuntu update for OpenSSL
- Ubuntu update for OpenSSL
- Gentoo update for OpenSSL
- Slackware Linux update for openssl
- SUSE Linux update for OpenSSL
- openSUSE update for openssl
- openSUSE update for openssl
- SUSE Linux update for OpenSSL 1.0
- SUSE Linux update for OpenSSL
- Red Hat update for openssl098e
- Red Hat update for openssl
- Red Hat update for openssl097a and openssl098e
- Red Hat update for openssl
- Red Hat update for openssl
- Multiple vulnerabilities in IBM FlashSystem 840
- Multiple vulnerabilities in IBM FlashSystem (and TMS RAMSAN) 710, 720, 810, and 820 systems
- Multiple vulnerabilities in HP OneView
- Man-in-the-Middle attack in HP Integrity SD2 CB900s i2 and i4
- Multiple vulnerabilities in HP Service Manager
- Man-in-the-Middle attack in HP Asset Manager, CloudSystem Chargeback
- Man-in-the-Middle attack in HP BladeSystem c-Class Virtual Connect Firmware
- Man-in-the-Middle attack in HP CloudSystem Foundation and HP CloudSystem Enterprise
- Man-in-the-Middle attack in HP Executive Scorecard
- Man-in-the-Middle attack in HP Cloud Service Automation
- Man-in-the-Middle attack in HP IDOL
- Multiple vulnerabilities in HP Operations Analytics
- Multiple vulnerabilities in HP Smart Update Manager (HP SUM)
- Man-in-the-Middle attack in HP Software Database and Middleware Automation
- Man-in-the-Middle attack in HP Server Automation
- Man-in-the-Middle attack in HP BladeSystem c-Class Onboard Administrator (OA)
- Multiple vulnerabilities in IBM BladeCenter Advanced Management Module
- Multiple vulnerabilities in HP 3PAR Service Processor (SP)
- Man-in-the-Middle attack in HP Command View for Tape Libraries (CVTL)
- Man-in-the-Middle attack in IBM TS2900
- Man-in-the-Middle attack in Lenovo SAN Volume Controller and Storwize Family
- Man-in-the-Middle attack in IBM SAN Volume Controller and Storwize Family
- Man-in-the-Middle attack in IBM XIV Gen2
- Man-in-the-Middle attack in IBM XIV Gen3 Storage System
- Fedora 21 update for mingw-openssl
- Fedora EPEL 7 update for mingw-openssl