CVE-2014-0195 is a critical buffer overflow vulnerability in OpenSSL versions prior to 0.9.8za, 1.0.0m, and 1.0.1h, specifically affecting the dtls1_reassemble_fragment function. This flaw, present for over 15 years, allows remote attackers to execute arbitrary code or cause a denial of service by sending malformed DTLS ClientHello messages with long non-initial fragments. With a CVSS score of 6.8 (medium severity) and an EPSS score indicating high exploitability, the vulnerability can be exploited remotely with medium attack complexity, leading to partial confidentiality, integrity, and availability impacts. While not listed in CISA KEV, a Metasploit module exists for denial-of-service, and it has garnered significant community discussion and media coverage, indicating its importance despite being marked as "Inactive" on the Hot List.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.9.8, < 0.9.8zaCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* | ||
>= 1.0.0, < 1.0.0mCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* | ||
>= 1.0.1, < 1.0.1hCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* | ||
>= 10.0.0, < 10.0.13CPE matchmatch criteria | cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:* | ||
42.1CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.