CVE-2014-3470 is a denial-of-service vulnerability in OpenSSL versions prior to 0.9.8za, 1.0.0m, and 1.0.1h, affecting products like Fedora, MariaDB, and Red Hat. It allows remote attackers to crash a client by triggering a NULL certificate value when an anonymous ECDH cipher suite is used. With a CVSS score of 4.3 (medium severity), this vulnerability has a network attack vector and medium attack complexity, leading to a partial availability impact. Although not listed in CISA's KEV catalog and lacking public exploit code, its high EPSS score and significant community discussion and media coverage suggest a notable level of concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.9.8zaCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* | ||
>= 1.0.0, < 1.0.0mCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* | ||
>= 1.0.1, < 1.0.1hCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* | ||
2.1CPE matchmatch criteria | cpe:2.3:a:redhat:storage:2.1:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.