{
  "id": "CVE-2014-0160",
  "url": "https://spydr.io/cve/CVE-2014-0160",
  "published": "2014-04-07T22:55:03.893Z",
  "modified": "2026-06-17T00:02:24.467Z",
  "score": 7.5,
  "severity": "high",
  "cvss_version": "3.1",
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
  "score_source": "NVD",
  "epss": 0.99999,
  "epss_percentile": 0.99997,
  "exploited": true,
  "kev": {
    "added": "2022-05-04",
    "due": "2022-05-25",
    "action": "Apply updates per vendor instructions.",
    "ransomware": "Unknown",
    "name": "OpenSSL Information Disclosure Vulnerability",
    "notes": "https://nvd.nist.gov/vuln/detail/CVE-2014-0160"
  },
  "ssvc_exploitation": "active",
  "vendors": [
    "openssl",
    "filezilla-project",
    "siemens",
    "intellian",
    "mitel",
    "opensuse",
    "canonical",
    "fedoraproject",
    "redhat",
    "debian"
  ],
  "products": [
    "openssl",
    "filezilla-project filezilla server",
    "siemens application processing engine firmware",
    "siemens cp 1543-1 firmware",
    "siemens simatic s7-1500 firmware",
    "siemens simatic s7-1500t firmware",
    "siemens elan-8.2",
    "siemens wincc open architecture",
    "intellian v100 firmware",
    "intellian v60 firmware",
    "mitel micollab",
    "mitel mivoice",
    "opensuse",
    "canonical ubuntu linux",
    "fedoraproject fedora",
    "redhat gluster storage",
    "redhat storage",
    "redhat virtualization",
    "redhat enterprise linux desktop",
    "redhat enterprise linux server"
  ],
  "cwes": [
    "CWE-125"
  ],
  "description": "The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.",
  "status": "Analyzed",
  "score_type": "Primary",
  "scores": {
    "cvss_v40": null,
    "cvss_v31": 7.5,
    "cvss_v30": null
  },
  "references": [
    {
      "url": "http://advisories.mageia.org/MGASA-2014-0165.html",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://blog.fox-it.com/2014/04/08/openssl-heartbleed-bug-live-blog/",
      "tags": [
        "Issue Tracking",
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://cogentdatahub.com/ReleaseNotes.html",
      "tags": [
        "Release Notes"
      ]
    },
    {
      "url": "http://download.schneider-electric.com/files?p_Doc_Ref=SEVD%202014-119-01",
      "tags": [
        "Broken Link"
      ]
    },
    {
      "url": "http://git.openssl.org/gitweb/?p=openssl.git%3Ba=commit%3Bh=96db9023b881d7cd9f379b0c154650d6c108e9a3",
      "tags": [
        "Broken Link"
      ]
    },
    {
      "url": "http://heartbleed.com/",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2014-April/131221.html",
      "tags": [
        "Broken Link",
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2014-April/131291.html",
      "tags": [
        "Broken Link",
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136473.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2014-04/msg00004.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2014-04/msg00005.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://lists.opensuse.org/opensuse-updates/2014-04/msg00061.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://marc.info/?l=bugtraq&m=139722163017074&w=2",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://marc.info/?l=bugtraq&m=139757726426985&w=2",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://marc.info/?l=bugtraq&m=139757819327350&w=2",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://marc.info/?l=bugtraq&m=139757919027752&w=2",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://marc.info/?l=bugtraq&m=139758572430452&w=2",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://marc.info/?l=bugtraq&m=139765756720506&w=2",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://marc.info/?l=bugtraq&m=139774054614965&w=2",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://marc.info/?l=bugtraq&m=139774703817488&w=2",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://marc.info/?l=bugtraq&m=139808058921905&w=2",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://marc.info/?l=bugtraq&m=139817685517037&w=2",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://marc.info/?l=bugtraq&m=139817727317190&w=2",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://marc.info/?l=bugtraq&m=139817782017443&w=2",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://marc.info/?l=bugtraq&m=139824923705461&w=2",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ]
    }
  ],
  "nvd_url": "https://nvd.nist.gov/vuln/detail/CVE-2014-0160",
  "covered_in": [],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
