Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · 1 min 99 bronnen 3 kritiek 3 vandaag
CVE's Videos

← Terug naar CVE-database

CVE-2014-0224

HIGH · 7.4 CVSS Gepubliceerd: CWE-326

Beschrijving

OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive information, via a crafted TLS handshake, aka the "CCS Injection" vulnerability.

Vendors

Openssl Redhat Fedoraproject Opensuse Filezilla-project Siemens Mariadb Python Nodejs

Affected products

Openssl Jboss Enterprise Application Platform Jboss Enterprise Web Platform Jboss Enterprise Web Server Storage Fedora Opensuse Enterprise Linux Filezilla Server Application Processing Engine Firmware Application Processing Engine Cp1543-1 Firmware Cp1543-1 S7-1500 Firmware S7-1500 Rox Firmware Rox Mariadb Python Node.js

References