Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2014-3513

38
FAUCET Score

CVE-2014-3513 describes a memory leak vulnerability in the DTLS SRTP extension of OpenSSL versions prior to 1.0.1j, specifically within the d1_srtp.c file. This flaw allows remote attackers to trigger a denial of service by sending a specially crafted handshake message, leading to excessive memory consumption. With a CVSS score of 7.1 (High) and a FAUCET Risk Score of 90/100, the vulnerability is remotely exploitable with medium attack complexity, resulting in a complete loss of availability. While there is no evidence of active exploitation, public exploit code, or KEV listing, the vulnerability has garnered some community discussion and media coverage, indicating awareness within the cybersecurity community.

Impacted Technologies

VendorProductVersion(s)CPE
1.0.1CPE matchmatch criteria
cpe:2.3:a:openssl:openssl:1.0.1:*:*:*:*:*:*:*
1.0.1CPE matchmatch criteria
cpe:2.3:a:openssl:openssl:1.0.1:beta1:*:*:*:*:*:*
1.0.1CPE matchmatch criteria
cpe:2.3:a:openssl:openssl:1.0.1:beta2:*:*:*:*:*:*
1.0.1CPE matchmatch criteria
cpe:2.3:a:openssl:openssl:1.0.1:beta3:*:*:*:*:*:*
1.0.1aCPE matchmatch criteria
cpe:2.3:a:openssl:openssl:1.0.1a:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

7.1HIGH

AV:N/AC:M/Au:N/C:N/I:N/A:C

Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
COMPLETE
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
8.6
Impact Score
6.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
37.07%
Probability of exploitation in next 30 days
EPSS Percentile
98.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.3707 is in the 96th percentile among its peer group of 8,920 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

gentoopatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: openssl-0:1.0.1e-30.el6_6.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: openssl-1:1.0.1e-34.el7_0.6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Storage 2.1Fixed in: openssl-0:1.0.1e-30.el6_6.2
View patch
redhatno patchvia redhat_api
Product: Red Hat Enterprise Virtualization 3Fixed in: mingw-virt-viewer

Vendor Advisories (1)

redhatCVE-2014-3513Important

openssl: SRTP memory leak causes crash when using specially-crafted handshake message

Oct 15, 2014

References

ftp.netbsd.org / pub/NetBSD/security/advisories/NetBSD-SA2014-015.txt.asc
advisories.mageia.org / MGASA-2014-0416.html
aix.software.ibm.com / aix/efixes/security/openssl_advisory11.asc
lists.apple.com / archives/security-announce/2015/Sep/msg00002.html
lists.opensuse.org / opensuse-security-announce/2014-10/msg00008.html
lists.opensuse.org / opensuse-security-announce/2014-11/msg00001.html
marc.info
marc.info
Patch
marc.info
marc.info
marc.info
marc.info
marc.info
marc.info
marc.info
rhn.redhat.com / errata/RHSA-2014-1652.html
rhn.redhat.com / errata/RHSA-2014-1692.html
blogs.oracle.com / sunsecurity/entry/multiple_vulnerabilities_in_openssl6
secunia.com / advisories/59627
secunia.com / advisories/61058
secunia.com / advisories/61073
secunia.com / advisories/61207
secunia.com / advisories/61298
secunia.com / advisories/61439
secunia.com / advisories/61837
secunia.com / advisories/61959
secunia.com / advisories/61990
secunia.com / advisories/62070
security.gentoo.org / glsa/glsa-201412-39.xml
Patch
git.openssl.org / gitweb
h20566.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
h20566.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
kc.mcafee.com / corporate/index
support.apple.com / HT205217
support.f5.com / kb/en-us/solutions/public/15000/700/sol15722.html
openssl.org / news/secadv_20141015.txt
Vendor Advisory
www-01.ibm.com / support/docview.wss
debian.org / security/2014/dsa-3053
mandriva.com / security/advisories
securityfocus.com / bid/70584
securitytracker.com / id/1031052
ubuntu.com / usn/USN-2385-1