Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2014-0160

99
FAUCET Score

CVE-2014-0160, known as Heartbleed, is a critical buffer over-read vulnerability in OpenSSL versions 1.0.1 through 1.0.1f. It allows remote attackers to extract sensitive information, such as private keys, from process memory by sending malformed Heartbeat Extension packets. This flaw affects a wide range of products including OpenSSL itself, Debian, Red Hat, and Splunk. Rated with a CVSS score of 7.5 (High), Heartbleed is easily exploitable over the network without authentication or user interaction, leading to a complete compromise of confidentiality. Its EPSS score of 0.9447 and FAUCET Risk Score of 100/100 highlight its extreme criticality and widespread impact. Heartbleed has been actively exploited in the wild and is listed on CISA's KEV catalog. Numerous exploit modules are publicly available, including Metasploit and Nuclei templates, along with multiple entries on ExploitDB. The vulnerability has garnered significant community discussion and media coverage, underscoring its historical importance and the widespread efforts to mitigate it.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.0.1, < 1.0.1gCPE matchmatch criteria
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
< 0.9.44CPE matchmatch criteria
cpe:2.3:a:filezilla-project:filezilla_server:*:*:*:*:*:*:*:*
2.0CPE matchmatch criteria
cpe:2.3:o:siemens:application_processing_engine_firmware:2.0:*:*:*:*:*:*:*
1.1CPE matchmatch criteria
cpe:2.3:o:siemens:cp_1543-1_firmware:1.1:*:*:*:*:*:*:*
1.5CPE matchmatch criteria
cpe:2.3:o:siemens:simatic_s7-1500_firmware:1.5:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
100.00%
Probability of exploitation in next 30 days
EPSS Percentile
100.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
Added to KEV · May 4, 2022
Metasploit: OpenSSL Heartbeat (Heartbleed) Information Leak · Apr 7, 2014
Nuclei: CVE-2014-0160 · Oct 24, 2024
ExploitDB: EDB-32998 · Apr 24, 2014
This CVE's current EPSS score of 1.0000 is in the 100th percentile among its peer group of 51,553 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (9)

asteriskpatch availablevia llm_extracted
Fixed in: 4.2.3
View patch
check_pointpatch availablevia llm_extracted
Fixed in: 4.2.3
View patch
oraclepatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: RHEV 3.X Hypervisor and Agents for RHEL-6Fixed in: rhev-hypervisor6-0:6.5-20140118.1.3.2.el6_5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: openssl-0:1.0.1e-16.el6_5.7
View patch
redhatpatch availablevia redhat_api
Product: RHEV Manager version 3.3Fixed in: spice-client-msi-0:3.3-12
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Storage 2.1Fixed in: openssl-0:1.0.1e-16.el6_5.7
View patch
redhatpatch availablevia redhat_api
Product: RHEV 3.X Hypervisor and Agents for RHEL-6Fixed in: rhev-hypervisor6-0:6.5-20140407.0.el6ev
View patch
wagopatch availablevia llm_extracted
Fixed in: ['8.0.3 Patch', '8.0.4 Patch', '8.0.5 Patch', '8.0.6 Patch', '8.0.7 Patch', '8.0.7']
View patch

Vendor Advisories (4)

redhatCVE-2014-0160Important

openssl: information disclosure in handling of TLS heartbeat extension packets

Apr 7, 2014
asteriskllm-asterisk-aa379a2bcf568c96

& more (a set of vulnerabilities) TLS heartbeat read overrun (4.1 line not affected)

check_pointllm-check_point-e6436752c177ae29

(a set of vulnerabilities) TLS heartbeat read overrun (4.1 line not affected)

wagollm-wago-6bcb1b423da83cbdHIGH

Patch ZCS8 OpenSSL for CVE-2014-0160

References

cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
advisories.mageia.org / MGASA-2014-0165.html
Third Party Advisory
blog.fox-it.com / 2014/04/08/openssl-heartbleed-bug-live-blog
Issue TrackingThird Party Advisory
cogentdatahub.com / ReleaseNotes.html
Release Notes
download.schneider-electric.com / files
Broken Link
git.openssl.org / gitweb
Broken Link
heartbleed.com
Third Party Advisory
lists.fedoraproject.org / pipermail/package-announce/2014-April/131221.html
Broken LinkThird Party Advisory
lists.fedoraproject.org / pipermail/package-announce/2014-April/131291.html
Broken LinkThird Party Advisory
lists.fedoraproject.org / pipermail/package-announce/2014-August/136473.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2014-04/msg00004.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2014-04/msg00005.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-updates/2014-04/msg00061.html
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
public.support.unisys.com / common/public/vulnerability/NVD_Detail_Rpt.aspx
Third Party Advisory
public.support.unisys.com / common/public/vulnerability/NVD_Detail_Rpt.aspx
Permissions RequiredThird Party Advisory
rhn.redhat.com / errata/RHSA-2014-0376.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2014-0377.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2014-0378.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2014-0396.html
Third Party Advisory
blog.torproject.org / blog/openssl-bug-cve-2014-0160
Issue Tracking
bugzilla.redhat.com / show_bug.cgi
Issue TrackingThird Party Advisory
cert-portal.siemens.com / productcert/pdf/ssa-635659.pdf
Third Party Advisory
code.google.com / p/mod-spdy/issues/detail
Issue Tracking
seclists.org / fulldisclosure/2014/Apr/109
Mailing ListThird Party Advisory
seclists.org / fulldisclosure/2014/Apr/173
Mailing ListThird Party Advisory
seclists.org / fulldisclosure/2014/Apr/190
Mailing ListThird Party Advisory
seclists.org / fulldisclosure/2014/Apr/90
Mailing ListThird Party Advisory
seclists.org / fulldisclosure/2014/Apr/91
Mailing ListThird Party Advisory
seclists.org / fulldisclosure/2014/Dec/23
Mailing ListThird Party Advisory
secunia.com / advisories/57347
Broken LinkThird Party Advisory
secunia.com / advisories/57483
Broken LinkThird Party Advisory
secunia.com / advisories/57721
Broken LinkThird Party Advisory
secunia.com / advisories/57836
Broken LinkThird Party Advisory
secunia.com / advisories/57966
Broken LinkThird Party Advisory
secunia.com / advisories/57968
Broken LinkThird Party Advisory
secunia.com / advisories/59139
Broken LinkThird Party Advisory
secunia.com / advisories/59243
Broken LinkThird Party Advisory
secunia.com / advisories/59347
Broken LinkThird Party Advisory
filezilla-project.org / versions.php
Release Notes
gist.github.com / chapmajs/10473815
Exploit
h20566.www2.hp.com / portal/site/hpsc/template.PAGE/public/kb/docDisplay
Broken Link
lists.apache.org / thread.html/ba661b0edd913b39ff129a32d855620dd861883ade05fd88a8ce517d%40%3Cdev.tomcat.apache.org%3E
Mailing ListPatchThird Party Advisory
lists.apache.org / thread.html/f8e0814e11c7f21f42224b6de111cb3f5e5ab5c15b78924c516d4ec2%40%3Cdev.tomcat.apache.org%3E
Mailing ListPatchThird Party Advisory
lists.apache.org / thread.html/re3b72cbb13e1dfe85c4a06959a3b6ca6d939b407ecca80db12b54220%40%3Cdev.tomcat.apache.org%3E
Mailing ListPatchThird Party Advisory
lists.apache.org / thread.html/rf8e8c091182b45daa50d3557cad9b10bb4198e3f08cf8f1c66a1b08d%40%3Cdev.tomcat.apache.org%3E
Mailing ListPatchThird Party Advisory
lists.balabit.hu / pipermail/syslog-ng-announce/2014-April/000184.html
Mailing ListThird Party Advisory
sku11army.blogspot.com / 2020/01/heartbleed-hearts-continue-to-bleed.html
ExploitPermissions RequiredThird Party Advisory
support.f5.com / kb/en-us/solutions/public/15000/100/sol15159.html
Third Party Advisory
support.f5.com / kb/en-us/solutions/public/15000/100/sol15159.html
Third Party Advisory
support.citrix.com / article/CTX140605
Third Party Advisory
cert.fi / en/reports/2014/vulnerability788210.html
Not ApplicableThird Party Advisory
mitel.com / en-ca/support/security-advisories/mitel-product-security-advisory-17-0008
Third Party Advisory
yunus-shn.medium.com / ricon-industrial-cellular-router-heartbleed-attack-2634221c02bd
Broken LinkExploitThird Party Advisory
tools.cisco.com / security/center/content/CiscoSecurityAdvisory/cisco-sa-20140409-heartbleed
Third Party Advisory
www-01.ibm.com / support/docview.wss
Third Party Advisory
www-01.ibm.com / support/docview.wss
Third Party Advisory
www-01.ibm.com / support/docview.wss
Third Party Advisory
www-01.ibm.com / support/docview.wss
Broken Link
apcmedia.com / salestools/SJHN-7RKGNM/SJHN-7RKGNM_R4_EN.pdf
Broken LinkThird Party Advisory
blackberry.com / btsc/KB35882
Broken Link
debian.org / security/2014/dsa-2896
Mailing ListThird Party Advisory
exploit-db.com / exploits/32745
ExploitThird Party AdvisoryVDB Entry
exploit-db.com / exploits/32764
ExploitThird Party AdvisoryVDB Entry
f-secure.com / en/web/labs_global/fsc-2014-1
Broken LinkThird Party Advisory
getchef.com / blog/2014/04/09/chef-server-11-0-12-release
Release Notes
getchef.com / blog/2014/04/09/chef-server-heartbleed-cve-2014-0160-releases
Third Party Advisory
getchef.com / blog/2014/04/09/enterprise-chef-11-1-3-release
Release Notes
getchef.com / blog/2014/04/09/enterprise-chef-1-4-9-release
Release Notes
innominate.com / data/downloads/manuals/mdm_1.5.2.1_Release_Notes.pdf
Not Applicable
kb.cert.org / vuls/id/720951
Third Party AdvisoryUS Government Resource
kerio.com / support/kerio-control/release-history
Broken LinkThird Party Advisory
mandriva.com / security/advisories
Broken LinkThird Party Advisory
openssl.org / news/secadv_20140407.txt
Broken LinkVendor Advisory
oracle.com / technetwork/topics/security/cpujul2014-1972956.html
PatchThird Party Advisory
oracle.com / technetwork/topics/security/opensslheartbleedcve-2014-0160-2188454.html
PatchThird Party Advisory
securityfocus.com / archive/1/534161/100/0/threaded
Broken LinkNot ApplicableThird Party AdvisoryVDB Entry
securityfocus.com / bid/66690
Broken LinkThird Party AdvisoryVDB Entry
securitytracker.com / id/1030026
Broken LinkThird Party AdvisoryVDB Entry
securitytracker.com / id/1030074
Broken LinkThird Party AdvisoryVDB Entry
securitytracker.com / id/1030077
Broken LinkThird Party AdvisoryVDB Entry
securitytracker.com / id/1030078
Broken LinkThird Party AdvisoryVDB Entry
securitytracker.com / id/1030079
Broken LinkThird Party AdvisoryVDB Entry
securitytracker.com / id/1030080
Broken LinkThird Party AdvisoryVDB Entry
securitytracker.com / id/1030081
Broken LinkThird Party AdvisoryVDB Entry
securitytracker.com / id/1030082
Broken LinkThird Party AdvisoryVDB Entry
splunk.com / view/SP-CAAAMB3
Third Party Advisory
symantec.com / security_response/securityupdates/detail.jsp
Third Party Advisory
ubuntu.com / usn/USN-2165-1
Third Party Advisory
us-cert.gov / ncas/alerts/TA14-098A
Third Party AdvisoryUS Government Resource
vmware.com / security/advisories/VMSA-2014-0012.html
Broken Link
websense.com / support/article/kbarticle/Vulnerabilities-resolved-in-TRITON-APX-Version-8-0
Broken Link