Information disclosure in OpenSSL - CVE-2014-3566
Published: January 20, 2017 / Updated: November 8, 2022
Vulnerability identifier: #VU5214
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-3566
CWE-ID: CWE-327
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a remote attacker to perform MitM attack.
The vulnerability exists due to usage of insecure SSLv3 protocol in OpenSSL. A remote attacker can force the current connection between user and server to be downgraded to SSLv3 protocol and then use padding-oracle attack on Cypher-block chaining (CBC) mode to decrypt encrypted communication.
Successful exploitation of the vulnerability may allow an attacker to read encrypted communications in clear text.
Note: The vulnerability is known as POODLE.
The vulnerability exists due to usage of insecure SSLv3 protocol in OpenSSL. A remote attacker can force the current connection between user and server to be downgraded to SSLv3 protocol and then use padding-oracle attack on Cypher-block chaining (CBC) mode to decrypt encrypted communication.
Successful exploitation of the vulnerability may allow an attacker to read encrypted communications in clear text.
Note: The vulnerability is known as POODLE.
Affected software
OpenSSL
Amazon Linux AMI
Gentoo Linux
Debian Linux
Fedora
SUSE Linux
Opensuse
Slackware Linux
Universal CMDB Browser
Universal CMDB Configuration Manager
Business Process Insight
Service Health Analyzer
AppPulse Active
HP Storage Essentials
Business Process Management
UCMDB Browser
HP Application Lifecycle Management
Systinet
Connect-IT
Project Portfolio Manager
HP Enterprise Maps
Server Automation Virtual Appliance
Automation Insight
Operations Analytics
Cloud Service Automation (CSA)
WMI Mapper
HP System Management Homepage
WebSphere Message Broker
Server Automation
Discovery and Dependency Mapping Inventory (DDMI)
Universal CMDB Foundation Software
HP IT Business Analytics
Universal Discovery
TippingPoint Next Generation Firewall
FlashSystem 840 9840-AE1 & 9843-AE1
FlashSystem V840 9846-AE1 & 9848-AE1
SSL for OpenVMS
System Storage Tape Controller 3592 Model C07
Integrated Lights-Out 2
TippingPoint Intrusion Prevention System (IPS) Local Security Manager (LSM)
3PAR Service Processors
TMS RAMSAN 710 & 810 Machine Type 9833 -AS1 & -AE1
FlashSystem 710 & 810 Machine Type 9830 -AS1 & -AE1
IBM FlashSystem 720 and 820 Machine Type 9831 –AS2 and -AE2
TMS RAMSAN 710 and 810 Machine Type 9834 -AS1 and -AE1
Vertica
Insight Remote Support Clients
HP Version Control Agent
HP Insight Control
Process Automation
Storage Data Protector
XIV Storage System Gen2
P6000 Command View Software
XIV Storage System Gen 3.0
Virtual Customer Access System (vCAS)
Instant Customer Access Server (iCAS)
TS2900 Tape Autoloader
HP AssetManager
HP Virtual Connect Enterprise Manager
Version Control Repository Manager
HPE Operations Orchestration
HP SiteScope
IBM Integration Bus
IBM BladeCenter Advanced Management Module
SUSE Studio Onsite
SUSE Manager
FileZilla
libuv
nodejs
mingw-openssl
openssl
libetpan
asterisk
subscription-manager
python-rhsm
fossil
claws-mail-plugins
claws-mail
HPE Integrated Lights-Out 3
HPE Integrated Lights-Out 4 (iLO 4)
BladeSystem c-Class Virtual Connect Firmware
SAN Volume Controller and Storwize Family
FOS Firmware
HP Onboard Administrator
HPE Service Manager
HP Network Automation
IBM Storwize V3500
IBM Storwize V3700
IBM Storwize V5000
IBM Storwize V7000
Amazon Linux AMI
Gentoo Linux
Debian Linux
Fedora
SUSE Linux
Opensuse
Slackware Linux
Universal CMDB Browser
Universal CMDB Configuration Manager
Business Process Insight
Service Health Analyzer
AppPulse Active
HP Storage Essentials
Business Process Management
UCMDB Browser
HP Application Lifecycle Management
Systinet
Connect-IT
Project Portfolio Manager
HP Enterprise Maps
Server Automation Virtual Appliance
Automation Insight
Operations Analytics
Cloud Service Automation (CSA)
WMI Mapper
HP System Management Homepage
WebSphere Message Broker
Server Automation
Discovery and Dependency Mapping Inventory (DDMI)
Universal CMDB Foundation Software
HP IT Business Analytics
Universal Discovery
TippingPoint Next Generation Firewall
FlashSystem 840 9840-AE1 & 9843-AE1
FlashSystem V840 9846-AE1 & 9848-AE1
SSL for OpenVMS
System Storage Tape Controller 3592 Model C07
Integrated Lights-Out 2
TippingPoint Intrusion Prevention System (IPS) Local Security Manager (LSM)
3PAR Service Processors
TMS RAMSAN 710 & 810 Machine Type 9833 -AS1 & -AE1
FlashSystem 710 & 810 Machine Type 9830 -AS1 & -AE1
IBM FlashSystem 720 and 820 Machine Type 9831 –AS2 and -AE2
TMS RAMSAN 710 and 810 Machine Type 9834 -AS1 and -AE1
Vertica
Insight Remote Support Clients
HP Version Control Agent
HP Insight Control
Process Automation
Storage Data Protector
XIV Storage System Gen2
P6000 Command View Software
XIV Storage System Gen 3.0
Virtual Customer Access System (vCAS)
Instant Customer Access Server (iCAS)
TS2900 Tape Autoloader
HP AssetManager
HP Virtual Connect Enterprise Manager
Version Control Repository Manager
HPE Operations Orchestration
HP SiteScope
IBM Integration Bus
IBM BladeCenter Advanced Management Module
SUSE Studio Onsite
SUSE Manager
FileZilla
libuv
nodejs
mingw-openssl
openssl
libetpan
asterisk
subscription-manager
python-rhsm
fossil
claws-mail-plugins
claws-mail
HPE Integrated Lights-Out 3
HPE Integrated Lights-Out 4 (iLO 4)
BladeSystem c-Class Virtual Connect Firmware
SAN Volume Controller and Storwize Family
FOS Firmware
HP Onboard Administrator
HPE Service Manager
HP Network Automation
IBM Storwize V3500
IBM Storwize V3700
IBM Storwize V5000
IBM Storwize V7000
How to mitigate CVE-2014-3566
Update OpenSSL to version 0.9.8zc, 1.0.0o or 1.0.1j.
WebSphere Message Broker - update to 8.0.0.6
IBM Integration Bus - update to 9.0.0.4
Discovery and Dependency Mapping Inventory (DDMI) - update to 9.32 update3-rev1
Universal CMDB Foundation Software - addressed in versions 10.01 CUP11, 10.11 CUP3
libuv - addressed in versions 0.10.29-1.el6, 0.10.29-1.el7, 0.10.29-1.fc21
nodejs - addressed in versions 0.10.33-1.el6, 0.10.33-1.el7, 0.10.33-1.fc21
mingw-openssl - update to 1.0.1j-1.fc21
openssl - update to 1.0.1j-1.fc21
TippingPoint Next Generation Firewall - update to 1.1.0.4155
FlashSystem 840 9840-AE1 & 9843-AE1 - update to 1.1.3.7
FlashSystem V840 9846-AE1 & 9848-AE1 - update to 1.1.3.7
SSL for OpenVMS - update to 1.4-495
libetpan - update to 1.6-1.fc21
asterisk - addressed in versions 1.8.31.1-1.el6, 11.13.1-1.fc21, 11.14.1-1.fc21
subscription-manager - update to 1.13.6-1.fc21
python-rhsm - update to 1.13.6-1.fc21
System Storage Tape Controller 3592 Model C07 - update to 1.25.3.20
fossil - addressed in versions 1.33-1.fc21, 1.33-1.fc22
HPE Integrated Lights-Out 3 - update to 1.82
HPE Integrated Lights-Out 4 (iLO 4) - update to 2.03
Integrated Lights-Out 2 - update to 2.27
TippingPoint Intrusion Prevention System (IPS) Local Security Manager (LSM) - addressed in versions 3.1.3.1325, 3.6.4.4113, 3.7.2.4252
claws-mail-plugins - update to 3.11.1-1.fc21
claws-mail - update to 3.11.1-2.fc21
IBM BladeCenter Advanced Management Module - update to 3.66N
3PAR Service Processors - addressed in versions 4.1.0.GA-97.P011, 4.2.0.GA-29.P003, 4.3.0.GA-17.P001
HP Onboard Administrator - update to 4.13
BladeSystem c-Class Virtual Connect Firmware - update to 4.40
TMS RAMSAN 710 & 810 Machine Type 9833 -AS1 & -AE1 - update to 5.6.2
FlashSystem 710 & 810 Machine Type 9830 -AS1 & -AE1 - update to 5.6.2
IBM FlashSystem 720 and 820 Machine Type 9831 –AS2 and -AE2 - update to 6.3.2
TMS RAMSAN 710 and 810 Machine Type 9834 -AS1 and -AE1 - update to 6.3.2
IBM Storwize V3500 - addressed in versions 7.1.0.12, 7.2.0.10, 7.3.0.8
IBM Storwize V3700 - addressed in versions 7.1.0.12, 7.2.0.10, 7.3.0.8
IBM Storwize V5000 - addressed in versions 7.1.0.12, 7.2.0.10, 7.3.0.8
SAN Volume Controller and Storwize Family - addressed in versions 7.1.0.12, 7.2.0.10, 7.3.0.8
Vertica - update to 7.1.2-3
Insight Remote Support Clients - update to 7.2
IBM Storwize V7000 - update to 7.2.0.10
FOS Firmware - addressed in versions 7.2.1d, 7.3.0c
HP Version Control Agent - update to 7.3.4
HP Virtual Connect Enterprise Manager - update to 7.4.1
Version Control Repository Manager - update to 7.4.1
HP Insight Control - update to 7.4.1
Process Automation - update to 7.5.2
HPE Service Manager - addressed in versions 7.11.752 p23, 9.21.755 P10, 9.34.4001 p4, 9.40.1002 p1
Storage Data Protector - addressed in versions 8.13_206, 9.03MMR
HP Network Automation - addressed in versions 9.22.02, 10.00.01
XIV Storage System Gen2 - update to 10.2.4.e-8
P6000 Command View Software - update to 10.3.7
XIV Storage System Gen 3.0 - update to 11.5.1
Virtual Customer Access System (vCAS) - update to 14.10-38402
Instant Customer Access Server (iCAS) - update to 14.11-38437
TS2900 Tape Autoloader - update to 0036
IBM Integration Bus - update to 9.0.0.4
Discovery and Dependency Mapping Inventory (DDMI) - update to 9.32 update3-rev1
Universal CMDB Foundation Software - addressed in versions 10.01 CUP11, 10.11 CUP3
libuv - addressed in versions 0.10.29-1.el6, 0.10.29-1.el7, 0.10.29-1.fc21
nodejs - addressed in versions 0.10.33-1.el6, 0.10.33-1.el7, 0.10.33-1.fc21
mingw-openssl - update to 1.0.1j-1.fc21
openssl - update to 1.0.1j-1.fc21
TippingPoint Next Generation Firewall - update to 1.1.0.4155
FlashSystem 840 9840-AE1 & 9843-AE1 - update to 1.1.3.7
FlashSystem V840 9846-AE1 & 9848-AE1 - update to 1.1.3.7
SSL for OpenVMS - update to 1.4-495
libetpan - update to 1.6-1.fc21
asterisk - addressed in versions 1.8.31.1-1.el6, 11.13.1-1.fc21, 11.14.1-1.fc21
subscription-manager - update to 1.13.6-1.fc21
python-rhsm - update to 1.13.6-1.fc21
System Storage Tape Controller 3592 Model C07 - update to 1.25.3.20
fossil - addressed in versions 1.33-1.fc21, 1.33-1.fc22
HPE Integrated Lights-Out 3 - update to 1.82
HPE Integrated Lights-Out 4 (iLO 4) - update to 2.03
Integrated Lights-Out 2 - update to 2.27
TippingPoint Intrusion Prevention System (IPS) Local Security Manager (LSM) - addressed in versions 3.1.3.1325, 3.6.4.4113, 3.7.2.4252
claws-mail-plugins - update to 3.11.1-1.fc21
claws-mail - update to 3.11.1-2.fc21
IBM BladeCenter Advanced Management Module - update to 3.66N
3PAR Service Processors - addressed in versions 4.1.0.GA-97.P011, 4.2.0.GA-29.P003, 4.3.0.GA-17.P001
HP Onboard Administrator - update to 4.13
BladeSystem c-Class Virtual Connect Firmware - update to 4.40
TMS RAMSAN 710 & 810 Machine Type 9833 -AS1 & -AE1 - update to 5.6.2
FlashSystem 710 & 810 Machine Type 9830 -AS1 & -AE1 - update to 5.6.2
IBM FlashSystem 720 and 820 Machine Type 9831 –AS2 and -AE2 - update to 6.3.2
TMS RAMSAN 710 and 810 Machine Type 9834 -AS1 and -AE1 - update to 6.3.2
IBM Storwize V3500 - addressed in versions 7.1.0.12, 7.2.0.10, 7.3.0.8
IBM Storwize V3700 - addressed in versions 7.1.0.12, 7.2.0.10, 7.3.0.8
IBM Storwize V5000 - addressed in versions 7.1.0.12, 7.2.0.10, 7.3.0.8
SAN Volume Controller and Storwize Family - addressed in versions 7.1.0.12, 7.2.0.10, 7.3.0.8
Vertica - update to 7.1.2-3
Insight Remote Support Clients - update to 7.2
IBM Storwize V7000 - update to 7.2.0.10
FOS Firmware - addressed in versions 7.2.1d, 7.3.0c
HP Version Control Agent - update to 7.3.4
HP Virtual Connect Enterprise Manager - update to 7.4.1
Version Control Repository Manager - update to 7.4.1
HP Insight Control - update to 7.4.1
Process Automation - update to 7.5.2
HPE Service Manager - addressed in versions 7.11.752 p23, 9.21.755 P10, 9.34.4001 p4, 9.40.1002 p1
Storage Data Protector - addressed in versions 8.13_206, 9.03MMR
HP Network Automation - addressed in versions 9.22.02, 10.00.01
XIV Storage System Gen2 - update to 10.2.4.e-8
P6000 Command View Software - update to 10.3.7
XIV Storage System Gen 3.0 - update to 11.5.1
Virtual Customer Access System (vCAS) - update to 14.10-38402
Instant Customer Access Server (iCAS) - update to 14.11-38437
TS2900 Tape Autoloader - update to 0036
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Multiple vulnerabilities in OpenSSL
- POODLE vulnerability in FileZilla
- Debian update for lighttpd
- Debian update for openssl
- Slackware Linux update for openssl
- openSUSE update for openssl
- SUSE Linux update for OpenSSL
- SUSE Linux update for OpenSSL
- SUSE Linux update for OpenSSL
- SUSE Linux update for OpenSSL
- SUSE Linux update for OpenSSL
- SUSE Linux update for openssl1
- SUSE Linux update for suseRegister
- Amazon Linux AMI update for openssl
- Amazon Linux AMI update for nss
- Gentoo update for claws-mail
- Multiple vulnerabilities in IBM Websphere Message Broker and IBM Integration Bus
- Information disclosure in IBM FlashSystem 840 and IBM FlashSystem V840
- Multiple vulnerabilities in IBM FlashSystem (and TMS RAMSAN) 710, 720, 810, and 820 systems
- Information disclosure in IBM FOS Firmware
- Information disclosure in HP IT Business Analytics
- Information disclosure in HP Universal CMDB Foundation, Discovery, Configuration Manager, and CMDB Browser
- Information disclosure in HP Discovery and Dependency Mapping Inventory (DDMI)
- Information disclosure in HP Service Manager
- Information disclosure in HP Operations Analytics
- Information disclosure in HP Business Process Insight (BPI)
- Information disclosure in HP Service Health Analyzer
- Information disclosure in HP AppPulse Active
- Information disclosure in HP Storage Essentials
- Information disclosure in HP Insight Remote Support Clients
- Information disclosure in HP Enterprise Maps
- Information disclosure in HP Cloud Service Automation
- Information disclosure in HP Business Process Management
- Information disclosure in HP UCMDB Browser
- Information disclosure in HP Asset Manager
- Information disclosure in HP Application Lifecycle Management
- Multiple vulnerabilities in HP Remote Device Access: Virtual Customer Access System (vCAS)
- Information disclosure in HP Remote Device Access: Instant Customer Access Server (iCAS)
- Information disclosure in HP Project Portfolio Manager
- Information disclosure in HP Integrated Lights-Out 2, 3, and 4
- Information disclosure in HP TippingPoint Intrusion Prevention System (IPS) Local Security Manager (LSM)
- Information disclosure in HP TippingPoint Next Generation Firewall (NGFW) Local Security Manager (LSM)
- Information disclosure in HP Data Protector
- Information disclosure in HP Vertica Analytics Platform
- Multiple vulnerabilities in HP Systems Insight Manager
- Multiple vulnerabilities in HP Insight Control server provisioning
- Information disclosure in HP Network Automation
- Information disclosure in HP Process Automation
- Multiple vulnerabilities in HP Version Control Repository Manager
- Multiple vulnerabilities in HP BladeSystem c-Class Virtual Connect Firmware
- Multiple vulnerabilities in HP Version Control Agent
- Information disclosure in HP BladeSystem c-Class Onboard Administrator
- Multiple vulnerabilities in HP Virtual Connect Enterprise Manager SDK
- Information disclosure in HP Automation Insight
- Information disclosure in HP Systinet
- Information disclosure in HP Connect-IT
- Information disclosure in HP SiteScope
- Information disclosure in HP Server Automation and Server Automation Virtual Appliance
- Information disclosure in HP Operations Orchestration
- Information disclosure in IBM BladeCenter Advanced Management Module
- Multiple vulnerabilities in HP SSL for OpenVMS
- Multiple vulnerabilities in HP 3PAR Service Processor (SP)
- Multiple vulnerabilities in HP P6000 Command View Software
- Information disclosure in IBM TS2900
- Multiple vulnerabilities in SAN Volume Controller and Storwize Family
- Information disclosure in IBM System Storage Tape Controller 3592 Model C07
- Multiple vulnerabilities in SAN Volume Controller and Storwize Family
- Information disclosure in IBM XIV Storage System Gen 2
- Information disclosure in IBM XIV Storage System Gen 3.0
- Fedora 21 update for openssl
- Fedora 21 update for asterisk
- Fedora EPEL 6 update for asterisk
- Fedora 21 update for python-rhsm, subscription-manager
- Fedora 21 update for claws-mail, claws-mail-plugins, libetpan
- Fedora 21 update for libuv, nodejs
- Fedora EPEL 7 update for libuv, nodejs
- Fedora EPEL 6 update for libuv, nodejs
- Fedora 21 update for asterisk
- Fedora 21 update for mingw-openssl
- Fedora 22 update for fossil
- Fedora 21 update for fossil