CVE-2014-0224
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive information, via a crafted TLS handshake, aka the "CCS Injection" vulnerability.
Published:Jun 5, 2014
Last Modified:Apr 12, 2025
EPS:Jun 5, 2014
EPSS Score:0.92939
CVSS Score:7.4
Affected Products
Vendor
Product
Action
Vendor
Fedoraproject
Product
Fedora
Fedoraproject
Fedora
Vendor
Filezilla-project
Product
Filezilla Server
Filezilla-project
Filezilla Server
Vendor
Mariadb
Product
Mariadb
Mariadb
Mariadb
Vendor
Nodejs
Product
Node.js
Nodejs
Node.js
Vendor
Openssl
Product
Openssl
Openssl
Openssl
Vendor
Opensuse
Product
Opensuse
Opensuse
Opensuse
Vendor
Python
Product
Python
Python
Python
Vendor
Redhat
Product
Enterprise Linux
Redhat
Enterprise Linux
Vendor
Redhat
Product
Jboss Enterprise Application Platform
Redhat
Jboss Enterprise Application Platform
Vendor
Redhat
Product
Jboss Enterprise Web Platform
Redhat
Jboss Enterprise Web Platform
Vendor
Redhat
Product
Jboss Enterprise Web Server
Redhat
Jboss Enterprise Web Server
Vendor
Redhat
Product
Rhel Els
Redhat
Rhel Els
Vendor
Redhat
Product
Rhel Eus
Redhat
Rhel Eus
Vendor
Redhat
Product
Rhel Mission Critical
Redhat
Rhel Mission Critical
Vendor
Redhat
Product
Storage
Redhat
Storage
Vendor
Siemens
Product
Application Processing Engine
Siemens
Application Processing Engine
Vendor
Siemens
Product
Application Processing Engine Firmware
Siemens
Application Processing Engine Firmware
Vendor
Siemens
Product
Cp1543-1
Siemens
Cp1543-1
Vendor
Siemens
Product
Cp1543-1 Firmware
Siemens
Cp1543-1 Firmware
Vendor
Siemens
Product
Rox
Siemens
Rox
Vendor
Siemens
Product
Rox Firmware
Siemens
Rox Firmware
Vendor
Siemens
Product
S7-1500
Siemens
S7-1500
Vendor
Siemens
Product
S7-1500 Firmware
Siemens
S7-1500 Firmware
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
