logo

CVE-2014-0160 - OpenSSL Information Disclosure Vulnerability

Project:OpenSSL

Product:OpenSSL

Date Added:2022-05-04Due Date:2022-05-25

Vulnerability Name

OpenSSL Information Disclosure Vulnerability

Description

The TLS and DTLS implementations in OpenSSL do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information.

Known To Be Used in Ransomware Campaigns?

Unknown

Action

Apply updates per vendor instructions.

Additional Notes

https://nvd.nist.gov/vuln/detail/CVE-2014-0160