SSL Protocol 3.0 Vulnerability in OpenSSL Products
CVE-2014-3566

3.4LOW

Key Information:

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC๐ŸŸฃ EPSS 94%

What is CVE-2014-3566?

The SSL Protocol 3.0 vulnerability allows attackers to exploit the nondeterministic CBC padding method used in OpenSSL, enabling man-in-the-middle attacks. This vulnerability can lead to the exposure of sensitive cleartext data via a padding-oracle attack, commonly referred to as the 'POODLE' exploit. Updating to newer versions that disable SSL 3.0 and implementing proper security measures can significantly mitigate this risk.

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

EPSS Score

94% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
3.4
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.