Information disclosure in OpenSSL - CVE-2014-3566

 

Information disclosure in OpenSSL - CVE-2014-3566

Published: January 20, 2017 / Updated: November 8, 2022


Vulnerability identifier: #VU5214
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-3566
CWE-ID: CWE-327
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to perform MitM attack.

The vulnerability exists due to usage of insecure SSLv3 protocol in OpenSSL. A remote attacker can force the current connection between user and server to be downgraded to SSLv3 protocol and then use padding-oracle attack on Cypher-block chaining (CBC) mode to decrypt encrypted communication.

Successful exploitation of the vulnerability may allow an attacker to read encrypted communications in clear text.

Note: The vulnerability is known as POODLE.

Affected software

OpenSSL
Amazon Linux AMI
Gentoo Linux
Debian Linux
Fedora
SUSE Linux
Opensuse
Slackware Linux
Universal CMDB Browser
Universal CMDB Configuration Manager
Business Process Insight
Service Health Analyzer
AppPulse Active
HP Storage Essentials
Business Process Management
UCMDB Browser
HP Application Lifecycle Management
Systinet
Connect-IT
Project Portfolio Manager
HP Enterprise Maps
Server Automation Virtual Appliance
Automation Insight
Operations Analytics
Cloud Service Automation (CSA)
WMI Mapper
HP System Management Homepage
WebSphere Message Broker
Server Automation
Discovery and Dependency Mapping Inventory (DDMI)
Universal CMDB Foundation Software
HP IT Business Analytics
Universal Discovery
TippingPoint Next Generation Firewall
FlashSystem 840 9840-AE1 & 9843-AE1
FlashSystem V840 9846-AE1 & 9848-AE1
SSL for OpenVMS
System Storage Tape Controller 3592 Model C07
Integrated Lights-Out 2
TippingPoint Intrusion Prevention System (IPS) Local Security Manager (LSM)
3PAR Service Processors
TMS RAMSAN 710 & 810 Machine Type 9833 -AS1 & -AE1
FlashSystem 710 & 810 Machine Type 9830 -AS1 & -AE1
IBM FlashSystem 720 and 820 Machine Type 9831 –AS2 and -AE2
TMS RAMSAN 710 and 810 Machine Type 9834 -AS1 and -AE1
Vertica
Insight Remote Support Clients
HP Version Control Agent
HP Insight Control
Process Automation
Storage Data Protector
XIV Storage System Gen2
P6000 Command View Software
XIV Storage System Gen 3.0
Virtual Customer Access System (vCAS)
Instant Customer Access Server (iCAS)
TS2900 Tape Autoloader
HP AssetManager
HP Virtual Connect Enterprise Manager
Version Control Repository Manager
HPE Operations Orchestration
HP SiteScope
IBM Integration Bus
IBM BladeCenter Advanced Management Module
SUSE Studio Onsite
SUSE Manager
FileZilla
libuv
nodejs
mingw-openssl
openssl
libetpan
asterisk
subscription-manager
python-rhsm
fossil
claws-mail-plugins
claws-mail
HPE Integrated Lights-Out 3
HPE Integrated Lights-Out 4 (iLO 4)
BladeSystem c-Class Virtual Connect Firmware
SAN Volume Controller and Storwize Family
FOS Firmware
HP Onboard Administrator
HPE Service Manager
HP Network Automation
IBM Storwize V3500
IBM Storwize V3700
IBM Storwize V5000
IBM Storwize V7000

How to mitigate CVE-2014-3566

Update OpenSSL to version 0.9.8zc, 1.0.0o or 1.0.1j.

WebSphere Message Broker - update to 8.0.0.6
IBM Integration Bus - update to 9.0.0.4
Discovery and Dependency Mapping Inventory (DDMI) - update to 9.32 update3-rev1
Universal CMDB Foundation Software - addressed in versions 10.01 CUP11, 10.11 CUP3
libuv - addressed in versions 0.10.29-1.el6, 0.10.29-1.el7, 0.10.29-1.fc21
nodejs - addressed in versions 0.10.33-1.el6, 0.10.33-1.el7, 0.10.33-1.fc21
mingw-openssl - update to 1.0.1j-1.fc21
openssl - update to 1.0.1j-1.fc21
TippingPoint Next Generation Firewall - update to 1.1.0.4155
FlashSystem 840 9840-AE1 & 9843-AE1 - update to 1.1.3.7
FlashSystem V840 9846-AE1 & 9848-AE1 - update to 1.1.3.7
SSL for OpenVMS - update to 1.4-495
libetpan - update to 1.6-1.fc21
asterisk - addressed in versions 1.8.31.1-1.el6, 11.13.1-1.fc21, 11.14.1-1.fc21
subscription-manager - update to 1.13.6-1.fc21
python-rhsm - update to 1.13.6-1.fc21
System Storage Tape Controller 3592 Model C07 - update to 1.25.3.20
fossil - addressed in versions 1.33-1.fc21, 1.33-1.fc22
HPE Integrated Lights-Out 3 - update to 1.82
HPE Integrated Lights-Out 4 (iLO 4) - update to 2.03
Integrated Lights-Out 2 - update to 2.27
TippingPoint Intrusion Prevention System (IPS) Local Security Manager (LSM) - addressed in versions 3.1.3.1325, 3.6.4.4113, 3.7.2.4252
claws-mail-plugins - update to 3.11.1-1.fc21
claws-mail - update to 3.11.1-2.fc21
IBM BladeCenter Advanced Management Module - update to 3.66N
3PAR Service Processors - addressed in versions 4.1.0.GA-97.P011, 4.2.0.GA-29.P003, 4.3.0.GA-17.P001
HP Onboard Administrator - update to 4.13
BladeSystem c-Class Virtual Connect Firmware - update to 4.40
TMS RAMSAN 710 & 810 Machine Type 9833 -AS1 & -AE1 - update to 5.6.2
FlashSystem 710 & 810 Machine Type 9830 -AS1 & -AE1 - update to 5.6.2
IBM FlashSystem 720 and 820 Machine Type 9831 –AS2 and -AE2 - update to 6.3.2
TMS RAMSAN 710 and 810 Machine Type 9834 -AS1 and -AE1 - update to 6.3.2
IBM Storwize V3500 - addressed in versions 7.1.0.12, 7.2.0.10, 7.3.0.8
IBM Storwize V3700 - addressed in versions 7.1.0.12, 7.2.0.10, 7.3.0.8
IBM Storwize V5000 - addressed in versions 7.1.0.12, 7.2.0.10, 7.3.0.8
SAN Volume Controller and Storwize Family - addressed in versions 7.1.0.12, 7.2.0.10, 7.3.0.8
Vertica - update to 7.1.2-3
Insight Remote Support Clients - update to 7.2
IBM Storwize V7000 - update to 7.2.0.10
FOS Firmware - addressed in versions 7.2.1d, 7.3.0c
HP Version Control Agent - update to 7.3.4
HP Virtual Connect Enterprise Manager - update to 7.4.1
Version Control Repository Manager - update to 7.4.1
HP Insight Control - update to 7.4.1
Process Automation - update to 7.5.2
HPE Service Manager - addressed in versions 7.11.752 p23, 9.21.755 P10, 9.34.4001 p4, 9.40.1002 p1
Storage Data Protector - addressed in versions 8.13_206, 9.03MMR
HP Network Automation - addressed in versions 9.22.02, 10.00.01
XIV Storage System Gen2 - update to 10.2.4.e-8
P6000 Command View Software - update to 10.3.7
XIV Storage System Gen 3.0 - update to 11.5.1
Virtual Customer Access System (vCAS) - update to 14.10-38402
Instant Customer Access Server (iCAS) - update to 14.11-38437
TS2900 Tape Autoloader - update to 0036

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins