Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2014-3511

18
FAUCET Score

CVE-2014-3511 describes a protocol downgrade vulnerability in OpenSSL versions prior to 1.0.1i, specifically within the ssl23_get_client_hello function. This flaw allows a man-in-the-middle attacker to force communication between a client and server to use TLS 1.0, even if both support more secure, later TLS versions, by manipulating ClientHello message fragmentation. With a CVSS score of 4.3, this vulnerability has a medium attack complexity and could lead to information integrity issues, though it does not directly impact confidentiality or availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
1.0.0CPE matchmatch criteria
cpe:2.3:a:openssl:openssl:1.0.0:*:*:*:*:*:*:*
1.0.0CPE matchmatch criteria
cpe:2.3:a:openssl:openssl:1.0.0:beta1:*:*:*:*:*:*
1.0.0CPE matchmatch criteria
cpe:2.3:a:openssl:openssl:1.0.0:beta2:*:*:*:*:*:*
1.0.0CPE matchmatch criteria
cpe:2.3:a:openssl:openssl:1.0.0:beta3:*:*:*:*:*:*
1.0.0CPE matchmatch criteria
cpe:2.3:a:openssl:openssl:1.0.0:beta4:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

4.3MEDIUM

AV:N/AC:M/Au:N/C:N/I:P/A:N

Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
8.6
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
13.33%
Probability of exploitation in next 30 days
EPSS Percentile
96.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.1333 is in the 96th percentile among its peer group of 19,958 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: openssl-0:1.0.1e-16.el6_5.15
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: openssl-1:1.0.1e-34.el7_0.4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Storage 2.1Fixed in: openssl-0:1.0.1e-16.el6_5.15
View patch
redhatpatch availablevia redhat_api
Product: RHEV 3.X Hypervisor and Agents for RHEL-6Fixed in: rhev-hypervisor6-0:6.6-20150123.1.el6ev
View patch
redhatpatch availablevia redhat_api
Product: RHEV Manager version 3.5Fixed in: spice-client-msi-0:3.5-2
View patch

Vendor Advisories (1)

redhatCVE-2014-3511Moderate

openssl: TLS protocol downgrade attack

Aug 6, 2014

References

ftp.netbsd.org / pub/NetBSD/security/advisories/NetBSD-SA2014-008.txt.asc
aix.software.ibm.com / aix/efixes/security/openssl_advisory10.asc
linux.oracle.com / errata/ELSA-2014-1052.html
lists.fedoraproject.org / pipermail/package-announce/2014-August/136470.html
lists.fedoraproject.org / pipermail/package-announce/2014-August/136473.html
lists.opensuse.org / opensuse-updates/2014-08/msg00036.html
marc.info
marc.info
marc.info
marc.info
marc.info
marc.info
marc.info
rhn.redhat.com / errata/RHSA-2015-0126.html
rhn.redhat.com / errata/RHSA-2015-0197.html
bugzilla.redhat.com / show_bug.cgi
secunia.com / advisories/58962
secunia.com / advisories/59700
secunia.com / advisories/59710
secunia.com / advisories/59756
secunia.com / advisories/59887
secunia.com / advisories/60022
secunia.com / advisories/60221
secunia.com / advisories/60377
secunia.com / advisories/60493
secunia.com / advisories/60684
secunia.com / advisories/60803
secunia.com / advisories/60810
secunia.com / advisories/60890
secunia.com / advisories/60917
secunia.com / advisories/60921
secunia.com / advisories/60938
secunia.com / advisories/61017
secunia.com / advisories/61043
secunia.com / advisories/61100
secunia.com / advisories/61139
secunia.com / advisories/61184
secunia.com / advisories/61775
secunia.com / advisories/61959
security.gentoo.org / glsa/glsa-201412-39.xml
exchange.xforce.ibmcloud.com / vulnerabilities/95162
git.openssl.org / gitweb
h20566.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
h20566.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
kc.mcafee.com / corporate/index
lists.balabit.hu / pipermail/syslog-ng-announce/2014-September/000196.html
support.citrix.com / article/CTX216642
techzone.ergon.ch / CVE-2014-3511
support.f5.com / kb/en-us/solutions/public/15000/500/sol15564.html
freebsd.org / security/advisories/FreeBSD-SA-14:18.openssl.asc
openssl.org / news/secadv_20140806.txt
Vendor Advisory
www-01.ibm.com / support/docview.wss
www-01.ibm.com / support/docview.wss
www-01.ibm.com / support/docview.wss
www-01.ibm.com / support/docview.wss
arubanetworks.com / support/alerts/aid-08182014.txt
debian.org / security/2014/dsa-2998
huawei.com / en/security/psirt/security-bulletins/security-advisories/hw-372998.htm
securityfocus.com / bid/69079
securitytracker.com / id/1030693
splunk.com / view/SP-CAAANHS
tenable.com / security/tns-2014-06