Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2014-3568

18
FAUCET Score

CVE-2014-3568 describes a vulnerability in OpenSSL versions prior to 0.9.8zc, 1.0.0o, and 1.0.1j, where the no-ssl3 build option is not properly enforced, allowing remote attackers to bypass intended access restrictions through an SSL 3.0 handshake. With a CVSS score of 4.3 (medium severity), this vulnerability has a network attack vector and medium attack complexity, potentially leading to partial integrity impact. There is no evidence of active exploitation, nor is there publicly available exploit code in Metasploit or ExploitDB. Community discussion and media coverage are minimal, with only one mention and one article, primarily related to the POODLE vulnerability (CVE-2014-3566).

Impacted Technologies

VendorProductVersion(s)CPE
<= 0.9.8zbCPE matchmatch criteria
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
1.0.0CPE matchmatch criteria
cpe:2.3:a:openssl:openssl:1.0.0:*:*:*:*:*:*:*
1.0.0CPE matchmatch criteria
cpe:2.3:a:openssl:openssl:1.0.0:beta1:*:*:*:*:*:*
1.0.0CPE matchmatch criteria
cpe:2.3:a:openssl:openssl:1.0.0:beta2:*:*:*:*:*:*
1.0.0CPE matchmatch criteria
cpe:2.3:a:openssl:openssl:1.0.0:beta3:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

4.3MEDIUM

AV:N/AC:M/Au:N/C:N/I:P/A:N

Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
8.6
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
13.98%
Probability of exploitation in next 30 days
EPSS Percentile
96.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.1398 is in the 96th percentile among its peer group of 19,956 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2014-3568Low

openssl: Build option no-ssl3 is incomplete

Oct 15, 2014

References

ftp.netbsd.org / pub/NetBSD/security/advisories/NetBSD-SA2014-015.txt.asc
lists.apple.com / archives/security-announce/2015/Jan/msg00003.html
lists.apple.com / archives/security-announce/2015/Sep/msg00002.html
lists.opensuse.org / opensuse-security-announce/2014-10/msg00008.html
lists.opensuse.org / opensuse-security-announce/2014-11/msg00001.html
lists.opensuse.org / opensuse-security-announce/2014-11/msg00003.html
lists.opensuse.org / opensuse-security-announce/2015-03/msg00027.html
lists.opensuse.org / opensuse-security-announce/2016-03/msg00011.html
marc.info
marc.info
marc.info
marc.info
marc.info
marc.info
marc.info
marc.info
blogs.oracle.com / sunsecurity/entry/multiple_vulnerabilities_in_openssl6
secunia.com / advisories/59627
secunia.com / advisories/61058
secunia.com / advisories/61073
secunia.com / advisories/61130
secunia.com / advisories/61207
secunia.com / advisories/61819
secunia.com / advisories/61959
secunia.com / advisories/62030
secunia.com / advisories/62070
secunia.com / advisories/62124
security.gentoo.org / glsa/glsa-201412-39.xml
exchange.xforce.ibmcloud.com / vulnerabilities/97037
git.openssl.org / gitweb
h20566.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
h20566.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
kc.mcafee.com / corporate/index
support.apple.com / HT205217
support.citrix.com / article/CTX216642
support.apple.com / HT204244
openssl.org / news/secadv_20141015.txt
Vendor Advisory
www-01.ibm.com / support/docview.wss
debian.org / security/2014/dsa-3053
securityfocus.com / bid/70585
securitytracker.com / id/1031053