CVE-2014-0224

Exp

OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive information, via a crafted TLS handshake, aka the "CCS Injection" vulnerability.

Published: 2014-06-05 Last update: 2026-05-06 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2014-0224 is rated High Exploit Risk (79.4/100): CVSS High severity, with high exploitation likelihood (EPSS 89.69%, 100th percentile). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Public exploit references (Exploit-DB) for CVE-2014-0224

EDB-ID Source Kind Published Link
nvd_ref exploit_tag Exploit-DB ↗

Exploit prediction scoring system (EPSS) score for CVE-2014-0224

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-04-27 89.79% 89.69% -0.09%
2 2026-04-23 92.69% 89.79% -2.90%
3 2026-04-19 92.69%

Full EPSS history (61 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2014-0224

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
7.4 3.1 HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N Click to expand
Attack vector (AV:N)
Could be attacked over the internet or any normal routed network—not just someone sitting at the machine.
Attack complexity (AC:H)
Even with access, the exploit needs extra luck, timing, or a fussy environment to actually work.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:H)
They could widely tamper with or forge data—trust in the data is badly hurt.
Availability (A:N)
Service keeps running; no real outage angle.
2.2 5.2 [email protected]
5.8 2.0 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:M)
Exploitation needs some favorable conditions, but not exceptional ones.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:P)
Partial confidentiality impact.
Integrity impact (I:P)
Partial integrity impact.
Availability impact (A:N)
No availability impact.
8.6 4.9 [email protected]

Weakness enumeration for CVE-2014-0224

OS Trackers for CVE-2014-0224

vendor priority summary link
debian not yet assigned CVE-2014-0224 not yet assigned priority: Debian including 1 source packages (openssl), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. https://security-tracker.debian.org/tracker/CVE-2014-0224
gentoo high CVE-2014-0224: 1 GLSA(s) (201407-05), 1 atom(s) (dev-libs/openssl); latest impact high. https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2014-0224
redhat high https://access.redhat.com/security/cve/CVE-2014-0224
suse high CVE-2014-0224 severity important: SUSE including 335 source package names (MozillaFirefox-68.2.0-78.51.4, MozillaFirefox-branding-SLED-68-21.9.8, …), 839 product×package rows across 88 product lines (Image SLES12-SP5-Azure-SAP-BYOS, Image SLES12-SP5-Azure-SAP-On-Demand, … (88 product lines)): Fixed 610, Known Not Affected 229. https://www.suse.com/security/cve/CVE-2014-0224/
ubuntu medium CVE-2014-0224 medium priority: Ubuntu including 2 source packages (openssl, openssl098), 10 status rows across 5 suites (lucid, precise, saucy, trusty, upstream): released 9, DNE 1. https://ubuntu.com/security/CVE-2014-0224

Affected software / configurations for CVE-2014-0224

Vendor Product Version Raw CPE
openssl openssl < 0.9.8za cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
openssl openssl >= 1.0.0, < 1.0.0m cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
openssl openssl >= 1.0.1, < 1.0.1h cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
redhat jboss_enterprise_application_platform 5.2.0 cpe:2.3:a:redhat:jboss_enterprise_application_platform:5.2.0:*:*:*:*:*:*:*
redhat jboss_enterprise_application_platform 6.2.3 cpe:2.3:a:redhat:jboss_enterprise_application_platform:6.2.3:*:*:*:*:*:*:*
redhat jboss_enterprise_web_platform 5.2.0 cpe:2.3:a:redhat:jboss_enterprise_web_platform:5.2.0:*:*:*:*:*:*:*
redhat jboss_enterprise_web_server 2.0.1 cpe:2.3:a:redhat:jboss_enterprise_web_server:2.0.1:*:*:*:*:*:*:*
redhat storage 2.1 cpe:2.3:a:redhat:storage:2.1:*:*:*:*:*:*:*
fedoraproject fedora 19 cpe:2.3:o:fedoraproject:fedora:19:*:*:*:*:*:*:*
fedoraproject fedora 20 cpe:2.3:o:fedoraproject:fedora:20:*:*:*:*:*:*:*
opensuse opensuse 13.1 cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*
opensuse opensuse 13.2 cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*
redhat enterprise_linux 4 cpe:2.3:o:redhat:enterprise_linux:4:*:*:*:*:*:*:*
redhat enterprise_linux 5 cpe:2.3:o:redhat:enterprise_linux:5:*:*:*:*:*:*:*
redhat enterprise_linux 6.0 cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
filezilla-project filezilla_server < 0.9.45 cpe:2.3:a:filezilla-project:filezilla_server:*:*:*:*:*:*:*:*
siemens application_processing_engine_firmware < 2.0.2 cpe:2.3:o:siemens:application_processing_engine_firmware:*:*:*:*:*:*:*:*
siemens cp1543-1_firmware < 1.1.25 cpe:2.3:o:siemens:cp1543-1_firmware:*:*:*:*:*:*:*:*
siemens s7-1500_firmware < 1.6 cpe:2.3:o:siemens:s7-1500_firmware:*:*:*:*:*:*:*:*
siemens rox_firmware < 1.16.1 cpe:2.3:o:siemens:rox_firmware:*:*:*:*:*:*:*:*
mariadb mariadb >= 10.0.0, < 10.0.13 cpe:2.3:a:mariadb:mariadb:*:*:*:*:*:*:*:*
python python >= 2.7.0, < 2.7.8 cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
python python >= 3.4.0, < 3.4.2 cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
nodejs node.js < 0.10.29 cpe:2.3:a:nodejs:node.js:*:*:*:*:*:*:*:*

References for CVE-2014-0224

URL Tags
http://aix.software.ibm.com/aix/efixes/security/openssl_advisory9.asc Third Party Advisory
http://ccsinjection.lepidum.co.jp Third Party Advisory
http://dev.mysql.com/doc/relnotes/workbench/en/wb-news-6-1-7.html Third Party Advisory
http://esupport.trendmicro.com/solution/en-US/1103813.aspx Third Party Advisory
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10629 Not Applicable
http://kb.juniper.net/InfoCenter/index?page=content&id=KB29195 Not Applicable
http://kb.juniper.net/InfoCenter/index?page=content&id=KB29217 Third Party Advisory
http://linux.oracle.com/errata/ELSA-2014-1053.html Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136470.html Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136473.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00027.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00016.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.html Third Party Advisory
http://lists.opensuse.org/opensuse-updates/2015-02/msg00030.html Third Party Advisory
http://marc.info/?l=bugtraq&m=140266410314613&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=140317760000786&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=140369637402535&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=140386311427810&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=140389274407904&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=140389355508263&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=140431828824371&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=140448122410568&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=140482916501310&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=140491231331543&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=140499864129699&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=140544599631400&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=140604261522465&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=140621259019789&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=140672208601650&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=140752315422991&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=140784085708882&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=140794476212181&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=140852757108392&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=140852826008699&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=140870499402361&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=140904544427729&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=140983229106599&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=141025641601169&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=141147110427269&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=141164638606214&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=141383410222440&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=141383465822787&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=141658880509699&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=142350350616251&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=142546741516006&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=142805027510172&w=2 Third Party Advisory
http://puppetlabs.com/security/cve/cve-2014-0224 Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2014-0624.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2014-0626.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2014-0627.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2014-0630.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2014-0631.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2014-0632.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2014-0633.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2014-0680.html Third Party Advisory
http://seclists.org/fulldisclosure/2014/Dec/23 Mailing List Third Party Advisory
http://seclists.org/fulldisclosure/2014/Jun/38 Mailing List Third Party Advisory
http://secunia.com/advisories/58128 Third Party Advisory
http://secunia.com/advisories/58337 Third Party Advisory
http://secunia.com/advisories/58385 Third Party Advisory
http://secunia.com/advisories/58433 Third Party Advisory
http://secunia.com/advisories/58492 Third Party Advisory
http://secunia.com/advisories/58579 Third Party Advisory
http://secunia.com/advisories/58615 Third Party Advisory
http://secunia.com/advisories/58639 Third Party Advisory
http://secunia.com/advisories/58660 Third Party Advisory
http://secunia.com/advisories/58667 Third Party Advisory
http://secunia.com/advisories/58713 Third Party Advisory
http://secunia.com/advisories/58714 Third Party Advisory
http://secunia.com/advisories/58716 Third Party Advisory
http://secunia.com/advisories/58719 Third Party Advisory
http://secunia.com/advisories/58742 Third Party Advisory
http://secunia.com/advisories/58743 Third Party Advisory
http://secunia.com/advisories/58745 Third Party Advisory
http://secunia.com/advisories/58759 Third Party Advisory
http://secunia.com/advisories/58930 Third Party Advisory
http://secunia.com/advisories/58939 Third Party Advisory
http://secunia.com/advisories/58945 Third Party Advisory
http://secunia.com/advisories/58977 Third Party Advisory
http://secunia.com/advisories/59004 Third Party Advisory
http://secunia.com/advisories/59012 Third Party Advisory
http://secunia.com/advisories/59040 Third Party Advisory
http://secunia.com/advisories/59043 Third Party Advisory
http://secunia.com/advisories/59055 Third Party Advisory
http://secunia.com/advisories/59063 Third Party Advisory
http://secunia.com/advisories/59093 Third Party Advisory
http://secunia.com/advisories/59101 Third Party Advisory
http://secunia.com/advisories/59120 Third Party Advisory
http://secunia.com/advisories/59126 Third Party Advisory
http://secunia.com/advisories/59132 Third Party Advisory
http://secunia.com/advisories/59135 Third Party Advisory
http://secunia.com/advisories/59142 Third Party Advisory
http://secunia.com/advisories/59162 Third Party Advisory
http://secunia.com/advisories/59163 Third Party Advisory
http://secunia.com/advisories/59167 Third Party Advisory
http://secunia.com/advisories/59175 Third Party Advisory
http://secunia.com/advisories/59186 Third Party Advisory
http://secunia.com/advisories/59188 Third Party Advisory
http://secunia.com/advisories/59189 Third Party Advisory
http://secunia.com/advisories/59190 Third Party Advisory
http://secunia.com/advisories/59191 Third Party Advisory
http://secunia.com/advisories/59192 Third Party Advisory
http://secunia.com/advisories/59202 Third Party Advisory
http://secunia.com/advisories/59211 Third Party Advisory
http://secunia.com/advisories/59214 Third Party Advisory
http://secunia.com/advisories/59215 Third Party Advisory
http://secunia.com/advisories/59223 Third Party Advisory
http://secunia.com/advisories/59231 Third Party Advisory
http://secunia.com/advisories/59264 Third Party Advisory
http://secunia.com/advisories/59282 Third Party Advisory
http://secunia.com/advisories/59284 Third Party Advisory
http://secunia.com/advisories/59287 Third Party Advisory
http://secunia.com/advisories/59300 Third Party Advisory
http://secunia.com/advisories/59301 Third Party Advisory
http://secunia.com/advisories/59305 Third Party Advisory
http://secunia.com/advisories/59306 Third Party Advisory
http://secunia.com/advisories/59310 Third Party Advisory
http://secunia.com/advisories/59325 Third Party Advisory
http://secunia.com/advisories/59338 Third Party Advisory
http://secunia.com/advisories/59342 Third Party Advisory
http://secunia.com/advisories/59347 Third Party Advisory
http://secunia.com/advisories/59354 Third Party Advisory
http://secunia.com/advisories/59362 Third Party Advisory
http://secunia.com/advisories/59364 Third Party Advisory
http://secunia.com/advisories/59365 Third Party Advisory
http://secunia.com/advisories/59368 Third Party Advisory
http://secunia.com/advisories/59370 Third Party Advisory
http://secunia.com/advisories/59374 Third Party Advisory
http://secunia.com/advisories/59375 Third Party Advisory
http://secunia.com/advisories/59380 Third Party Advisory
http://secunia.com/advisories/59383 Third Party Advisory
http://secunia.com/advisories/59389 Third Party Advisory
http://secunia.com/advisories/59413 Third Party Advisory
http://secunia.com/advisories/59429 Third Party Advisory
http://secunia.com/advisories/59435 Third Party Advisory
http://secunia.com/advisories/59437 Third Party Advisory
http://secunia.com/advisories/59438 Third Party Advisory
http://secunia.com/advisories/59440 Third Party Advisory
http://secunia.com/advisories/59441 Third Party Advisory
http://secunia.com/advisories/59442 Third Party Advisory
http://secunia.com/advisories/59444 Third Party Advisory
http://secunia.com/advisories/59445 Third Party Advisory
http://secunia.com/advisories/59446 Third Party Advisory
http://secunia.com/advisories/59447 Third Party Advisory
http://secunia.com/advisories/59448 Third Party Advisory
http://secunia.com/advisories/59449 Third Party Advisory
http://secunia.com/advisories/59450 Third Party Advisory
http://secunia.com/advisories/59451 Third Party Advisory
http://secunia.com/advisories/59454 Third Party Advisory
http://secunia.com/advisories/59459 Third Party Advisory
http://secunia.com/advisories/59460 Third Party Advisory
http://secunia.com/advisories/59483 Third Party Advisory
http://secunia.com/advisories/59490 Third Party Advisory
http://secunia.com/advisories/59491 Third Party Advisory
http://secunia.com/advisories/59495 Third Party Advisory
http://secunia.com/advisories/59502 Third Party Advisory
http://secunia.com/advisories/59506 Third Party Advisory
http://secunia.com/advisories/59514 Third Party Advisory
http://secunia.com/advisories/59518 Third Party Advisory
http://secunia.com/advisories/59525 Third Party Advisory
http://secunia.com/advisories/59528 Third Party Advisory
http://secunia.com/advisories/59529 Third Party Advisory
http://secunia.com/advisories/59530 Third Party Advisory
http://secunia.com/advisories/59589 Third Party Advisory
http://secunia.com/advisories/59602 Third Party Advisory
http://secunia.com/advisories/59655 Third Party Advisory
http://secunia.com/advisories/59659 Third Party Advisory
http://secunia.com/advisories/59661 Third Party Advisory
http://secunia.com/advisories/59666 Third Party Advisory
http://secunia.com/advisories/59669 Third Party Advisory
http://secunia.com/advisories/59677 Third Party Advisory
http://secunia.com/advisories/59721 Third Party Advisory
http://secunia.com/advisories/59784 Third Party Advisory
http://secunia.com/advisories/59824 Third Party Advisory
http://secunia.com/advisories/59827 Third Party Advisory
http://secunia.com/advisories/59878 Third Party Advisory
http://secunia.com/advisories/59885 Third Party Advisory
http://secunia.com/advisories/59894 Third Party Advisory
http://secunia.com/advisories/59916 Third Party Advisory
http://secunia.com/advisories/59990 Third Party Advisory
http://secunia.com/advisories/60049 Third Party Advisory
http://secunia.com/advisories/60066 Third Party Advisory
http://secunia.com/advisories/60176 Third Party Advisory
http://secunia.com/advisories/60522 Third Party Advisory
http://secunia.com/advisories/60567 Third Party Advisory
http://secunia.com/advisories/60571 Third Party Advisory
http://secunia.com/advisories/60577 Third Party Advisory
http://secunia.com/advisories/60819 Third Party Advisory
http://secunia.com/advisories/61254 Third Party Advisory
http://secunia.com/advisories/61815 Third Party Advisory
http://security.gentoo.org/glsa/glsa-201407-05.xml Third Party Advisory
http://support.apple.com/kb/HT6443 Third Party Advisory
http://support.citrix.com/article/CTX140876 Third Party Advisory
http://support.f5.com/kb/en-us/solutions/public/15000/300/sol15325.html Third Party Advisory
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140605-openssl Third Party Advisory
http://www-01.ibm.com/support/docview.wss?uid=isg400001841 Third Party Advisory
http://www-01.ibm.com/support/docview.wss?uid=isg400001843 Third Party Advisory
http://www-01.ibm.com/support/docview.wss?uid=nas8N1020163 Third Party Advisory
http://www-01.ibm.com/support/docview.wss?uid=nas8N1020172 Third Party Advisory
http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004690 Third Party Advisory
cvelogic Threat Intelligence