SSL Protocol 3.0 Vulnerability in OpenSSL Products
CVE-2014-3566
Key Information:
- Vendor
Redhat
- Status
- Vendor
- CVE Published:
- 15 October 2014
Badges
What is CVE-2014-3566?
The SSL Protocol 3.0 vulnerability allows attackers to exploit the nondeterministic CBC padding method used in OpenSSL, enabling man-in-the-middle attacks. This vulnerability can lead to the exposure of sensitive cleartext data via a padding-oracle attack, commonly referred to as the 'POODLE' exploit. Updating to newer versions that disable SSL 3.0 and implementing proper security measures can significantly mitigate this risk.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
EPSS Score
94% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved