EXPOSURES › CVE-2014-0160
CVE-2014-0160
HIGH ⌖ ON CISA KEV · EXPLOITEDOpenSSL's mishandling of Heartbeat Extension packets allowed remote attackers to extract sensitive data from TLS/DTLS connections.
This vulnerability exposed sensitive information transmitted over encrypted channels, directly impacting CMMC/NIST 800-171 requirements for protecting confidentiality and integrity. DIB organizations must ensure OpenSSL is patched to prevent data exfiltration and maintain compliance with security controls.
Shame score — A known, actively exploited vulnerability in a foundational cryptographic library that allowed remote attackers to bypass encryption and steal data, demonstrating severe negligence in patch management and supply chain security.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
The TLS and DTLS implementations in OpenSSL do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information.