Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2014-0076

18
FAUCET Score

CVE-2014-0076 describes a side-channel vulnerability in the Montgomery ladder implementation of OpenSSL versions up to 1.0.0l. This flaw allows local attackers to potentially recover ECDSA nonces by observing non-constant-time swap operations via a FLUSH+RELOAD cache attack. The vulnerability has a low CVSS score of 1.9, indicating a local attack vector with medium complexity and a partial impact on confidentiality. While there is no known active exploitation or publicly available exploit code, the vulnerability has garnered some community discussion and media coverage, suggesting it was a notable concern at the time of its discovery.

Impacted Technologies

VendorProductVersion(s)CPE
<= 1.0.0lCPE matchmatch criteria
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
0.9.1cCPE matchmatch criteria
cpe:2.3:a:openssl:openssl:0.9.1c:*:*:*:*:*:*:*
0.9.2bCPE matchmatch criteria
cpe:2.3:a:openssl:openssl:0.9.2b:*:*:*:*:*:*:*
0.9.3CPE matchmatch criteria
cpe:2.3:a:openssl:openssl:0.9.3:*:*:*:*:*:*:*
0.9.3aCPE matchmatch criteria
cpe:2.3:a:openssl:openssl:0.9.3a:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

1.9LOW

AV:L/AC:M/Au:N/C:P/I:N/A:N

Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
Access Vector
LOCAL
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
3.4
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
0.94%
Probability of exploitation in next 30 days
EPSS Percentile
57.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0094 is in the 96th percentile among its peer group of 747 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2014-0076Moderate

openssl: ECDSA nonces susceptible to Yarom/Benger flush+reload cache side-channel attack

Feb 14, 2014

References

advisories.mageia.org / MGASA-2014-0165.html
eprint.iacr.org / 2014/140
git.openssl.org / gitweb
kb.juniper.net / InfoCenter/index
lists.opensuse.org / opensuse-security-announce/2016-03/msg00011.html
lists.opensuse.org / opensuse-updates/2014-04/msg00007.html
marc.info
marc.info
marc.info
marc.info
marc.info
marc.info
marc.info
marc.info
marc.info
bugs.gentoo.org / show_bug.cgi
bugzilla.novell.com / show_bug.cgi
secunia.com / advisories/58492
secunia.com / advisories/58727
secunia.com / advisories/58939
secunia.com / advisories/59040
secunia.com / advisories/59162
secunia.com / advisories/59175
secunia.com / advisories/59264
secunia.com / advisories/59300
secunia.com / advisories/59364
secunia.com / advisories/59374
secunia.com / advisories/59413
secunia.com / advisories/59438
secunia.com / advisories/59445
secunia.com / advisories/59450
secunia.com / advisories/59454
secunia.com / advisories/59490
secunia.com / advisories/59495
secunia.com / advisories/59514
secunia.com / advisories/59655
secunia.com / advisories/59721
secunia.com / advisories/60571
h20566.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
kc.mcafee.com / corporate/index
support.apple.com / kb/HT6443
tools.cisco.com / security/center/content/CiscoSecurityAdvisory/cisco-sa-20140605-openssl
www-01.ibm.com / support/docview.wss
www-01.ibm.com / support/docview.wss
www-01.ibm.com / support/docview.wss
www-01.ibm.com / support/docview.wss
www-01.ibm.com / support/docview.wss
www-01.ibm.com / support/docview.wss
www-01.ibm.com / support/docview.wss
www-01.ibm.com / support/docview.wss
www-01.ibm.com / support/docview.wss
www-01.ibm.com / support/docview.wss
www-01.ibm.com / support/docview.wss
www-01.ibm.com / support/docview.wss
huawei.com / en/security/psirt/security-bulletins/security-advisories/hw-345106.htm
mandriva.com / security/advisories
mandriva.com / security/advisories
novell.com / support/kb/doc.php
novell.com / support/kb/doc.php
openssl.org / news/secadv_20140605.txt
oracle.com / technetwork/security-advisory/cpuoct2017-3236626.html
oracle.com / technetwork/topics/security/cpujan2015-1972971.html
securityfocus.com / bid/66363
ubuntu.com / usn/USN-2165-1