CISA Known Exploited Vulnerability

CVE-2014-0160

OpenSSL · OpenSSL

OpenSSL Information Disclosure Vulnerability

Date added
BOD 22-01 due date
CWE CWE-125
Ransomware Unknown

CISA description

The TLS and DTLS implementations in OpenSSL do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information.

Required action

Apply updates per vendor instructions.