CVE-2014-0224, also known as "CCS Injection," is a critical vulnerability in OpenSSL versions prior to 0.9.8za, 1.0.0m, and 1.0.1h. It allows man-in-the-middle attackers to force the use of a zero-length master key during TLS handshakes, impacting various products including fedoraproject, mariadb, nodejs, and siemens. With a CVSS score of 7.4 (High) and an EPSS score indicating high exploitability, this flaw enables session hijacking and sensitive information disclosure through a crafted TLS handshake. While not listed in KEV, Metasploit modules exist for detection, and the vulnerability garnered significant community discussion and media coverage, indicating widespread awareness and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.9.8zaCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* | ||
>= 1.0.0, < 1.0.0mCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* | ||
>= 1.0.1, < 1.0.1hCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* | ||
5.2.0CPE matchmatch criteria | cpe:2.3:a:redhat:jboss_enterprise_application_platform:5.2.0:*:*:*:*:*:*:* | ||
6.2.3CPE matchmatch criteria | cpe:2.3:a:redhat:jboss_enterprise_application_platform:6.2.3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.