Assessment
Why it matters
CISA lists this vulnerability as known to be exploited; exploitation is confirmed; EPSS is 100.0%; technical severity is CVSS 7.5.
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.
Who should care
- Teams operating Symantec Messaging Gateway, Ubuntu Linux, Debian Linux +25 more
- Vulnerability and exposure management teams
- Security operations teams monitoring exploitation activity
Response plan
What I would do
- Confirm whether Symantec Messaging Gateway, Ubuntu Linux, Debian Linux +25 more is present in the environment.
- Identify affected versions and establish whether vulnerable services are exposed or reachable.
- Oracle Security patch Cpujul2014 1972956
- Review relevant security telemetry for evidence of attempted or successful exploitation.
- Document the remediation decision and track it to verified completion.
Treatment intelligence
Remediation intelligence
Vendor sources are listed before government and third-party guidance. Confirm product applicability and change prerequisites before deployment.
Patch
- Oracle Security patch Cpujul2014 1972956Oracle · Vendor sourceVerification pending ↗
- Oracle Security patch Opensslheartbleedcve 2014 0160 2188454Oracle · Vendor sourceVerification pending ↗
- F5 Security patch Sol15159F5 · Vendor sourceVerification pending ↗
- F5 Security patch Sol15159F5 · Vendor sourceVerification pending ↗
- Lists Apache Security patchLists ApacheVerification pending ↗
- Lists Apache Security patchLists ApacheVerification pending ↗
Upgrade
- Cogentdatahub Security release notes ReleaseNotesCogentdatahubVerification pending ↗
- Getchef Security release notes Chef Server 11 0 12 ReleaseGetchefVerification pending ↗
- Getchef Security release notes Enterprise Chef 1 4 9 ReleaseGetchefVerification pending ↗
- Getchef Security release notes Enterprise Chef 11 1 3 ReleaseGetchefVerification pending ↗
- Filezilla Project Security release notes VersionsFilezilla ProjectVerification pending ↗
Advisory
- Cisco Security advisory Cisco Sa 20140409 HeartbleedCisco · Vendor sourceVerification pending ↗
- IBM Security advisory Docview.wssIBM · Vendor sourceVerification pending ↗
- Debian Security advisory Dsa 2896Debian · Vendor sourceVerification pending ↗
- VMware Security advisory VMSA-2014-0012VMware · Vendor sourceVerification pending ↗
- Google Security advisory DetailGoogle · Vendor sourceVerification pending ↗
Technical details
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- CWE
- CWE-125
- Affected versions
- Broadcom Symantec Messaging Gateway (Version 10.6.0 | Version 10.6.1); Canonical Ubuntu Linux (Version 12.04 | Version 12.10 | Version 13.10); Debian Debian Linux (Version 6.0 | Version 7.0 | Version 8.0); Fedoraproject Fedora (Version 19 | Version 20); Filezilla-project Filezilla Server (End Excluding 0.9.44); Intellian V100 Firmware (Version 1.20 | Version 1.21 | Version 1.24); Intellian V60 Firmware (Version 1.15 | Version 1.25); Mitel Micollab (Version 6.0 | Version 7.0 | Version 7.1 | Version 7.2)
- Fixed versions
- Filezilla-project Filezilla Server (Fixed from 0.9.44); Openssl Openssl (Fixed from 1.0.1g); Siemens Elan-8.2 (Fixed from 8.3.3); Splunk Splunk (Fixed from 6.0.3)
- Published
- 7 April 2014
- Attack vector
- Network
- Privileges required
- None
- User interaction
- None
Signal timeline
- CVE published
- Added to CISA KEV
- Latest EPSS score: 100.0%
- Signal calculated at 83
External references
- Red Hat Third-party advisory RHSA 2014 0376
- Red Hat Third-party advisory RHSA 2014 0377
- Red Hat Third-party advisory RHSA 2014 0378
- Red Hat Third-party advisory RHSA 2014 0396
- Citrix Third-party advisory CTX140605
- IBM Third-party advisory Docview.wss
- IBM Third-party advisory Docview.wss
- IBM Third-party advisory Docview.wss
- Ubuntu Third-party advisory USN-2165-1
- Red Hat Third-party advisory Show Bug.cgi
- CERT/CC Government advisory 720951
- CISA Government advisory CVE-2014-0160