CVE-2014-0224
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive information, via a crafted TLS handshake, aka the "CCS Injection" vulnerability.
- Affected products
- Alt Linux, Centos, Check Point Gaia, Cisco Ios, Cisco Ios Xr, Hp-Ux, Huawei Vrp, Ibm Aix
- Openssl
- < 0.9.8za, 1.0.0m, 1.0.1h
- Fix
- Available
- CVSS 3.1
- 7.4 HIGH
- EPSS
- 95.3% (100th percentile)
- Weakness
- CWE-326
- NVD status
- Modified
- Published
- 2014-06-05
CVE-2014-0224 at NVD
18 known exploits for CVE-2014-0224
Proof-of-concept code and exploit modules indexed by Sploitus
a2sv
a2sv
A2SV--SSL-VUL-Scan
OpenSSL-CCS-Inject-Test
CVE-2014-0224
openssl-ccs-cve-2014-0224
CVE-2014-0224
ccs-eval
SSL Labs API Client
OpenSSL Server-Side ChangeCipherSpec Injection Scanner
OpenSSL SSL/TLS MITM Vulnerability (CVE-2014-0224)
yawast - The YAWAST Antecedent Web Application Security Toolkit
MassBleed - Mass SSL Vulnerability Scanner
SSL Labs API Client
Exploit for Inadequate Encryption Strength in Openssl
Exploit for Inadequate Encryption Strength in Openssl
Exploit for Inadequate Encryption Strength in Openssl
OpenSSL Server-Side ChangeCipherSpec Injection Scanner