Information disclosure in OpenSSL - CVE-2014-0160
Published: January 25, 2017 / Updated: May 4, 2022
Vulnerability identifier: #VU5373
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-0160
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
The vulnerability is being exploited in the wild
Vulnerability details
The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.
The weakness exists due to an error in the TLS/DTLS heartbeat functionality. A remote attacker can read system memory contents without needing to log on to the server and retrieve private keys, passwords or other sensitive information
Successful exploitation of the vulnerability results in information disclosure on the vulnerable system.
Note: the vulnerability was being actively exploited.
The weakness exists due to an error in the TLS/DTLS heartbeat functionality. A remote attacker can read system memory contents without needing to log on to the server and retrieve private keys, passwords or other sensitive information
Successful exploitation of the vulnerability results in information disclosure on the vulnerable system.
Note: the vulnerability was being actively exploited.
Affected software
OpenSSL
Debian Linux
Gentoo Linux
Amazon Linux AMI
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Opensuse
Slackware Linux
UCMDB Configuration Manager
UCMDB Browser
TippingPoint Next Generation Firewall
Virtual Connect Support Utility (VCSU)
Data ONTAP SMI-S Agent
Insight Management VCEM Web Client SDK (VCEMSDK)
CloudSystem Foundation
Connect-IT
Server Automation
Network Interactive Voice Response (NIVR)
Multimedia Service Environment (MSE)
3PAR OS
HP Insight Control
HP Version Control Agent
XIV Gen3
BladeSystem c-Class Virtual Connect Firmware
HP Onboard Administrator
HPE Service Manager
Red Hat Virtualization
Autonomy WorkSite Server
openssl-solibs
openssl
dev-libs/openssl
HP Smart Update Manager
HP Systems Insight Manager
Version Control Repository Manager
HP AssetManager
IBM Storwize V3700
IBM Storwize V7000
IBM Storwize V5000
IBM Storwize V3500
Debian Linux
Gentoo Linux
Amazon Linux AMI
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Opensuse
Slackware Linux
UCMDB Configuration Manager
UCMDB Browser
TippingPoint Next Generation Firewall
Virtual Connect Support Utility (VCSU)
Data ONTAP SMI-S Agent
Insight Management VCEM Web Client SDK (VCEMSDK)
CloudSystem Foundation
Connect-IT
Server Automation
Network Interactive Voice Response (NIVR)
Multimedia Service Environment (MSE)
3PAR OS
HP Insight Control
HP Version Control Agent
XIV Gen3
BladeSystem c-Class Virtual Connect Firmware
HP Onboard Administrator
HPE Service Manager
Red Hat Virtualization
Autonomy WorkSite Server
openssl-solibs
openssl
dev-libs/openssl
HP Smart Update Manager
HP Systems Insight Manager
Version Control Repository Manager
HP AssetManager
IBM Storwize V3700
IBM Storwize V7000
IBM Storwize V5000
IBM Storwize V3500
How to mitigate CVE-2014-0160
Update to version 1.0.1g or later.
TippingPoint Next Generation Firewall - update to 1.1.0.4150
Virtual Connect Support Utility (VCSU) - update to 1.9.1
Data ONTAP SMI-S Agent - update to 5.1P1
BladeSystem c-Class Virtual Connect Firmware - addressed in versions 4.10B, 4.20B
HP Onboard Administrator - addressed in versions 4.12, 4.21
CloudSystem Foundation - update to 8.02
HPE Service Manager - update to 9.33.3000 p3
openssl-solibs - update to 1.0.1g
openssl - update to 1.0.1g
dev-libs/openssl - update to 1.0.1g
Network Interactive Voice Response (NIVR) - addressed in versions 2.0.7 Reactive Patch 004, 2.1.0 Reactive Patch 004
Multimedia Service Environment (MSE) - update to 2.1.2
3PAR OS - addressed in versions 3.1.2 MU1, 3.1.2 MU2, 3.1.2 MU3, 3.1.3 P01
HP Smart Update Manager - update to 6.3.1
IBM Storwize V3700 - addressed in versions 6.4.1.9, 7.1.0.9, 7.2.0.5
IBM Storwize V7000 - addressed in versions 6.4.1.9, 7.1.0.9, 7.2.0.5
IBM Storwize V5000 - addressed in versions 6.4.1.9, 7.1.0.9, 7.2.0.5
IBM Storwize V3500 - addressed in versions 6.4.1.9, 7.1.0.9, 7.2.0.5
HP Systems Insight Manager - addressed in versions 7.2.3, 7.3.2
HP Insight Control - update to 7.3.1
Version Control Repository Manager - update to 7.3.2
HP Version Control Agent - update to 7.3.2
HP AssetManager - update to 9.40.10535 p3
XIV Gen3 - addressed in versions 11.3.1.b, 11.4.1.b
Virtual Connect Support Utility (VCSU) - update to 1.9.1
Data ONTAP SMI-S Agent - update to 5.1P1
BladeSystem c-Class Virtual Connect Firmware - addressed in versions 4.10B, 4.20B
HP Onboard Administrator - addressed in versions 4.12, 4.21
CloudSystem Foundation - update to 8.02
HPE Service Manager - update to 9.33.3000 p3
openssl-solibs - update to 1.0.1g
openssl - update to 1.0.1g
dev-libs/openssl - update to 1.0.1g
Network Interactive Voice Response (NIVR) - addressed in versions 2.0.7 Reactive Patch 004, 2.1.0 Reactive Patch 004
Multimedia Service Environment (MSE) - update to 2.1.2
3PAR OS - addressed in versions 3.1.2 MU1, 3.1.2 MU2, 3.1.2 MU3, 3.1.3 P01
HP Smart Update Manager - update to 6.3.1
IBM Storwize V3700 - addressed in versions 6.4.1.9, 7.1.0.9, 7.2.0.5
IBM Storwize V7000 - addressed in versions 6.4.1.9, 7.1.0.9, 7.2.0.5
IBM Storwize V5000 - addressed in versions 6.4.1.9, 7.1.0.9, 7.2.0.5
IBM Storwize V3500 - addressed in versions 6.4.1.9, 7.1.0.9, 7.2.0.5
HP Systems Insight Manager - addressed in versions 7.2.3, 7.3.2
HP Insight Control - update to 7.3.1
Version Control Repository Manager - update to 7.3.2
HP Version Control Agent - update to 7.3.2
HP AssetManager - update to 9.40.10535 p3
XIV Gen3 - addressed in versions 11.3.1.b, 11.4.1.b
Links to Public Exploits and PoC-codes
- Exploit #4728 - ssl-heartbleed.nse (Nmap NSE script that discovers/exploits Heartbleed/CVE-2014-0160) (October 21, 2020)
- Exploit #4547 - Heartexploit (Aquí está mi nuevo y primer exploit web, este exploit ataca a la vulnerabilidad de HeartBleed (CVE-2014-0160) espero que os guste.) (September 1, 2020)
- Exploit #3077 - heartbleed (Simple OpenSSL TLS Heartbeat (CVE-2014-0160) Scanner and Exploit (Multiple SSL/TLS versions)) (July 15, 2020)
- Exploit #2110 - CVE-2014-0160 (openssl Heart Bleed Exploit: CVE-2014-0160 Mass Security Auditor) (March 18, 2020)
- Exploit #2111 - ssl-heartbleed.nse (Nmap NSE script that discovers/exploits Heartbleed/CVE-2014-0160.) (March 18, 2020)
- Exploit #2115 - heartbleed-PoC (:broken_heart: Hearbleed exploit to retrieve sensitive information CVE-2014-0160 :broken_heart:) (March 18, 2020)
- Exploit #1871 - pacemaker (Heartbleed (CVE-2014-0160) client exploit) (March 18, 2020)
- Exploit #1934 - Heartexploit (Aquí está mi nuevo y primer exploit web, este exploit ataca a la vulnerabilidad de HeartBleed (CVE-2014-0160) espero que os guste.) (March 18, 2020)
- Exploit #40 - OpenSSL Heartbeat (Heartbleed) Client Memory Exposure (March 18, 2020)
- Exploit #41 - OpenSSL Heartbeat (Heartbleed) Information Leak (March 18, 2020)
- Exploit #908 - OpenSSL TLS Heartbeat Extension - 'Heartbleed' Information Leak Exploit (2) (DTLS Support) (March 18, 2020)
- Exploit #909 - OpenSSL TLS Heartbeat Extension - 'Heartbleed' Information Leak Exploit (1) (March 18, 2020)
- Exploit #910 - OpenSSL 1.0.1f TLS Heartbeat Extension - 'Heartbleed' Memory Disclosure (Multiple SSL/TLS versions) (March 18, 2020)
- Exploit #911 - OpenSSL TLS Heartbeat Extension - ''Heartbleed' Memory Disclosure (March 18, 2020)
External References
Related Security Bulletins
- Information disclosure in OpenSSL aka Heartbleed
- Debian update for openssl
- openSUSE update for openssl
- openSUSE update for openssl
- Red Hat update for rhev-hypervisor6
- Red Hat update for rhev-hypervisor6
- Red Hat update for openssl
- Amazon Linux AMI update for openssl
- Information disclosure in HP Software Server Automation
- Information disclosure in HP Software Service Manager
- Information disclosure in HP TippingPoint NGFW
- Information disclosure in HP Multimedia Service Environment (MSE), (HP Network Interactive Voice Response (NIVR))
- Information disclosure in HP Insight Control Server Deployment on Linux and Windows
- Information disclosure in HP CloudSystem Foundation and HP CloudSystem Enterprise Software
- Information disclosure in HP BladeSystem c-Class Onboard Administrator (OA)
- Information disclosure in HP Version Control Agent (VCA) and Version Control Repository Manager (VCRM)
- Information disclosure in HP Software Asset Manager
- Information disclosure in HP BladeSystem c-Class Virtual Connect Support Utility (VCSU)
- Information disclosure in HP Software Connect-IT
- Information disclosure in HP Insight Management VCEM Web Client SDK (VCEMSDK)
- Information disclosure in HP Software UCMDB Browser and Configuration Manager
- Information disclosure in HP Systems Insight Manager
- Information disclosure in HP Smart Update Manager (SUM)
- Information disclosure in HP Software Autonomy WorkSite Server
- Information disclosure in HP Virtual Connect Firmware
- Information disclosure in HP 3PAR OS
- Information disclosure in IBM N Series Data ONTAP SMI-S Agent
- Multiple vulnerabilities in SAN Volume Controller and Storwize Family
- Information disclosure in IBM XIV Gen3
- Gentoo update for OpenSSL
- Slackware Linux update for openssl