Skip to content
COOEY

EXPOSURES › CVE-2014-0160

CVE-2014-0160

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-05-04 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2014-0160 ↗
⌖ EXPLOITED IN THE WILD SHAME 75/100 exploited-in-wildunpatcheddata-breach

OpenSSL's mishandling of Heartbeat Extension packets allowed remote attackers to extract sensitive data from TLS/DTLS connections.

This vulnerability exposed sensitive information transmitted over encrypted channels, directly impacting CMMC/NIST 800-171 requirements for protecting confidentiality and integrity. DIB organizations must ensure OpenSSL is patched to prevent data exfiltration and maintain compliance with security controls.

Shame score — A known, actively exploited vulnerability in a foundational cryptographic library that allowed remote attackers to bypass encryption and steal data, demonstrating severe negligence in patch management and supply chain security.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

The TLS and DTLS implementations in OpenSSL do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.