CVE-2014-0160, known as Heartbleed, is a critical buffer over-read vulnerability in OpenSSL versions 1.0.1 through 1.0.1f. It allows remote attackers to extract sensitive information, such as private keys, from process memory by sending malformed Heartbeat Extension packets. This flaw affects a wide range of products including OpenSSL itself, Debian, Red Hat, and Splunk. Rated with a CVSS score of 7.5 (High), Heartbleed is easily exploitable over the network without authentication or user interaction, leading to a complete compromise of confidentiality. Its EPSS score of 0.9447 and FAUCET Risk Score of 100/100 highlight its extreme criticality and widespread impact. Heartbleed has been actively exploited in the wild and is listed on CISA's KEV catalog. Numerous exploit modules are publicly available, including Metasploit and Nuclei templates, along with multiple entries on ExploitDB. The vulnerability has garnered significant community discussion and media coverage, underscoring its historical importance and the widespread efforts to mitigate it.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.0.1, < 1.0.1gCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* | ||
< 0.9.44CPE matchmatch criteria | cpe:2.3:a:filezilla-project:filezilla_server:*:*:*:*:*:*:*:* | ||
2.0CPE matchmatch criteria | cpe:2.3:o:siemens:application_processing_engine_firmware:2.0:*:*:*:*:*:*:* | ||
1.1CPE matchmatch criteria | cpe:2.3:o:siemens:cp_1543-1_firmware:1.1:*:*:*:*:*:*:* | ||
1.5CPE matchmatch criteria | cpe:2.3:o:siemens:simatic_s7-1500_firmware:1.5:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
openssl: information disclosure in handling of TLS heartbeat extension packets
Apr 7, 2014& more (a set of vulnerabilities) TLS heartbeat read overrun (4.1 line not affected)
(a set of vulnerabilities) TLS heartbeat read overrun (4.1 line not affected)
Patch ZCS8 OpenSSL for CVE-2014-0160