CVE-2014-3512

Multiple buffer overflows in crypto/srp/srp_lib.c in the SRP implementation in OpenSSL 1.0.1 before 1.0.1i allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via an invalid SRP (1) g, (2) A, or (3) B parameter.

Published: 2014-08-13 Last update: 2026-05-06 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2014-3512 is rated High Risk (69.8/100): CVSS High severity, with high exploitation likelihood (EPSS 74.08%, 99th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. EPSS rose +33.87% over the last day, indicating growing attacker interest. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2014-3512

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 40.21% 74.08% +33.87%
2 2026-04-21 44.21% 40.21% -4.00%
3 2026-04-15 44.21%

Full EPSS history (54 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2014-3512

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
7.5 2.0 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:P)
Partial confidentiality impact.
Integrity impact (I:P)
Partial integrity impact.
Availability impact (A:P)
Partial availability impact.
10.0 6.4 [email protected]

Weakness enumeration for CVE-2014-3512

OS Trackers for CVE-2014-3512

vendor priority summary link
debian not yet assigned CVE-2014-3512 not yet assigned priority: Debian including 1 source packages (openssl), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. https://security-tracker.debian.org/tracker/CVE-2014-3512
gentoo normal CVE-2014-3512: 1 GLSA(s) (201412-39), 1 atom(s) (dev-libs/openssl); latest impact normal. https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2014-3512
redhat medium https://access.redhat.com/security/cve/CVE-2014-3512
suse high CVE-2014-3512 severity important: SUSE including 134 source package names (compat-openssl098, libcrypto38-2.5.0-1.1, …), 335 product×package rows across 51 product lines (SUSE CaaS Platform 4.0, SUSE Enterprise Storage 6, … (51 product lines)): Fixed 170, Known Not Affected 165. https://www.suse.com/security/cve/CVE-2014-3512/
ubuntu medium CVE-2014-3512 medium priority: Ubuntu including 2 source packages (openssl, openssl098), 8 status rows across 4 suites (lucid, precise, trusty, upstream): not-affected 3, released 3, DNE 2. https://ubuntu.com/security/CVE-2014-3512

Affected software / configurations for CVE-2014-3512

Vendor Product Version Raw CPE
openssl openssl 1.0.0 cpe:2.3:a:openssl:openssl:1.0.0:*:*:*:*:*:*:*
openssl openssl 1.0.0 cpe:2.3:a:openssl:openssl:1.0.0:beta1:*:*:*:*:*:*
openssl openssl 1.0.0 cpe:2.3:a:openssl:openssl:1.0.0:beta2:*:*:*:*:*:*
openssl openssl 1.0.0 cpe:2.3:a:openssl:openssl:1.0.0:beta3:*:*:*:*:*:*
openssl openssl 1.0.0 cpe:2.3:a:openssl:openssl:1.0.0:beta4:*:*:*:*:*:*
openssl openssl 1.0.0 cpe:2.3:a:openssl:openssl:1.0.0:beta5:*:*:*:*:*:*
openssl openssl 1.0.0a cpe:2.3:a:openssl:openssl:1.0.0a:*:*:*:*:*:*:*
openssl openssl 1.0.0b cpe:2.3:a:openssl:openssl:1.0.0b:*:*:*:*:*:*:*
openssl openssl 1.0.0c cpe:2.3:a:openssl:openssl:1.0.0c:*:*:*:*:*:*:*
openssl openssl 1.0.0d cpe:2.3:a:openssl:openssl:1.0.0d:*:*:*:*:*:*:*
openssl openssl 1.0.0e cpe:2.3:a:openssl:openssl:1.0.0e:*:*:*:*:*:*:*
openssl openssl 1.0.0f cpe:2.3:a:openssl:openssl:1.0.0f:*:*:*:*:*:*:*
openssl openssl 1.0.0g cpe:2.3:a:openssl:openssl:1.0.0g:*:*:*:*:*:*:*
openssl openssl 1.0.0h cpe:2.3:a:openssl:openssl:1.0.0h:*:*:*:*:*:*:*
openssl openssl 1.0.0i cpe:2.3:a:openssl:openssl:1.0.0i:*:*:*:*:*:*:*
openssl openssl 1.0.0j cpe:2.3:a:openssl:openssl:1.0.0j:*:*:*:*:*:*:*
openssl openssl 1.0.0k cpe:2.3:a:openssl:openssl:1.0.0k:*:*:*:*:*:*:*
openssl openssl 1.0.0l cpe:2.3:a:openssl:openssl:1.0.0l:*:*:*:*:*:*:*
openssl openssl 1.0.0m cpe:2.3:a:openssl:openssl:1.0.0m:*:*:*:*:*:*:*
openssl openssl 1.0.1 cpe:2.3:a:openssl:openssl:1.0.1:*:*:*:*:*:*:*
openssl openssl 1.0.1 cpe:2.3:a:openssl:openssl:1.0.1:beta1:*:*:*:*:*:*
openssl openssl 1.0.1 cpe:2.3:a:openssl:openssl:1.0.1:beta2:*:*:*:*:*:*
openssl openssl 1.0.1 cpe:2.3:a:openssl:openssl:1.0.1:beta3:*:*:*:*:*:*
openssl openssl 1.0.1a cpe:2.3:a:openssl:openssl:1.0.1a:*:*:*:*:*:*:*
openssl openssl 1.0.1b cpe:2.3:a:openssl:openssl:1.0.1b:*:*:*:*:*:*:*
openssl openssl 1.0.1c cpe:2.3:a:openssl:openssl:1.0.1c:*:*:*:*:*:*:*
openssl openssl 1.0.1d cpe:2.3:a:openssl:openssl:1.0.1d:*:*:*:*:*:*:*
openssl openssl 1.0.1e cpe:2.3:a:openssl:openssl:1.0.1e:*:*:*:*:*:*:*
openssl openssl 1.0.1f cpe:2.3:a:openssl:openssl:1.0.1f:*:*:*:*:*:*:*
openssl openssl 1.0.1g cpe:2.3:a:openssl:openssl:1.0.1g:*:*:*:*:*:*:*
openssl openssl 1.0.1h cpe:2.3:a:openssl:openssl:1.0.1h:*:*:*:*:*:*:*

References for CVE-2014-3512

URL Tags
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2014-008.txt.asc
http://aix.software.ibm.com/aix/efixes/security/openssl_advisory10.asc
http://lists.opensuse.org/opensuse-updates/2014-08/msg00036.html
http://marc.info/?l=bugtraq&m=142660345230545&w=2
http://secunia.com/advisories/59700
http://secunia.com/advisories/59710
http://secunia.com/advisories/59756
http://secunia.com/advisories/60022
http://secunia.com/advisories/60221
http://secunia.com/advisories/60493
http://secunia.com/advisories/60803
http://secunia.com/advisories/60810
http://secunia.com/advisories/60917
http://secunia.com/advisories/60921
http://secunia.com/advisories/61017
http://secunia.com/advisories/61100
http://secunia.com/advisories/61171
http://secunia.com/advisories/61184
http://secunia.com/advisories/61775
http://secunia.com/advisories/61959
http://security.gentoo.org/glsa/glsa-201412-39.xml
http://support.f5.com/kb/en-us/solutions/public/15000/500/sol15565.html
http://www-01.ibm.com/support/docview.wss?uid=nas8N1020240
http://www-01.ibm.com/support/docview.wss?uid=swg21682293
http://www-01.ibm.com/support/docview.wss?uid=swg21683389
http://www-01.ibm.com/support/docview.wss?uid=swg21686997
http://www.debian.org/security/2014/dsa-2998
http://www.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-372998.htm
http://www.securityfocus.com/bid/69083
http://www.securitytracker.com/id/1030693
http://www.tenable.com/security/tns-2014-06
https://exchange.xforce.ibmcloud.com/vulnerabilities/95158
https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commit%3Bh=4a23b12a031860253b58d503f296377ca076427b
https://lists.balabit.hu/pipermail/syslog-ng-announce/2014-September/000196.html
https://www.freebsd.org/security/advisories/FreeBSD-SA-14:18.openssl.asc
https://www.openssl.org/news/secadv_20140806.txt Vendor Advisory
cvelogic Threat Intelligence