CVE-2014-0221 describes a denial-of-service vulnerability in the dtls1_get_message_fragment function within OpenSSL versions prior to 0.9.8za, 1.0.0m, and 1.0.1h. This flaw allows a remote attacker to crash a client by sending a malformed DTLS hello message during an invalid DTLS handshake, impacting various products including fedoraproject, mariadb, and redhat. The vulnerability has a CVSS score of 4.3, indicating a medium severity. It can be exploited remotely with medium attack complexity, resulting in a partial denial of service (client crash). Its high FAUCET Risk Score of 98/100 and EPSS score of 0.69435 suggest a significant potential for impact. While there is no known active exploitation or publicly available exploit code in Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered substantial community discussion and media coverage, indicating a high level of awareness and concern within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.9.8, < 0.9.8zaCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* | ||
>= 1.0.0, < 1.0.0mCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* | ||
>= 1.0.1, < 1.0.1hCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* | ||
2.1CPE matchmatch criteria | cpe:2.3:a:redhat:storage:2.1:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.