---
cve: "CVE-2014-0160"
severity: "HIGH"
cvss: 7.5
epss: "100%"
vendor: "n/a"
kev: true
exploited: true
published: "2014-04-07 22:55:03"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-17T17:39:05+02:00"
---

# CVE-2014-0160

> 7.5 HIGH · ⚠️ CISA KEV (1597 Tage) · 🔓 Exploited · 🧪 PoC

## Beschreibung

The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Keine | good |
| A Verfügbarkeit | Keine | good |

## Exploit-Evidenz

- [EDB-32998 — OpenSSL TLS Heartbeat Extension - 'Heartbleed' Information Leak (2) (DTLS Support)](https://www.exploit-db.com/exploits/32998) ✅
- [EDB-32791 — OpenSSL TLS Heartbeat Extension - 'Heartbleed' Information Leak (1)](https://www.exploit-db.com/exploits/32791) ✅
- [EDB-32764 — OpenSSL 1.0.1f TLS Heartbeat Extension - 'Heartbleed' Memory Disclosure (Multiple SSL/TLS Versions)](https://www.exploit-db.com/exploits/32764) ✅
- [EDB-32745 — OpenSSL TLS Heartbeat Extension - 'Heartbleed' Memory Disclosure](https://www.exploit-db.com/exploits/32745) ✅

## Referenzen

- <https://support.f5.com/kb/en-us/solutions/public/15000/100/sol15159.html?sr=36517217>
- <http://www.securitytracker.com/id/1030077>
- <http://seclists.org/fulldisclosure/2014/Apr/90>
- <http://www.getchef.com/blog/2014/04/09/chef-server-heartbleed-cve-2014-0160-releases/>
- <http://www.debian.org/security/2014/dsa-2896>
- <http://marc.info/?l=bugtraq&m=139774054614965&w=2>
- <http://marc.info/?l=bugtraq&m=139889113431619&w=2>
- <http://rhn.redhat.com/errata/RHSA-2014-0396.html>
- <http://marc.info/?l=bugtraq&m=139835815211508&w=2>
- <http://marc.info/?l=bugtraq&m=141287864628122&w=2>
- <http://www.kb.cert.org/vuls/id/720951>
- <http://www.splunk.com/view/SP-CAAAMB3>
- <http://marc.info/?l=bugtraq&m=139905295427946&w=2>
- <http://www.websense.com/support/article/kbarticle/Vulnerabilities-resolved-in-TRITON-APX-Version-8-0>
- <http://www.apcmedia.com/salestools/SJHN-7RKGNM/SJHN-7RKGNM_R4_EN.pdf>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2014-0160) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
