CVE-2014-0160

openssl, filezilla-project filezilla server, siemens application processing engine firmware

Published 7 Apr 2014 · updated 17 Jun 2026 · Analyzed

7.5 High · CVSS 3.1, NVD

Exploited in the wild

CISA added this to its Known Exploited Vulnerabilities catalog on 4 May 2022, with a remediation deadline of 25 May 2022 for US federal agencies.

Required action: Apply updates per vendor instructions.

Description

The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.

References