← back
CVE-2014-3566lowCWE-329

CVE-2014-3566

45Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendcvss 3.4epss 100%
from disclosure to weapon0 days
Published on NVDOct 15
metasploitOct 14
exploitation probability
100%top 1% of all CVEs
observed exploitation
nono source reports it
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Affected
15 products (27 components)
Red Hat Enterprise Linux 6 · Red Hat Enterprise Virtualization 3 · Red Hat Enterprise Linux 5 · Red Hat Enterprise Linux 7 · Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) · and others 10
no_fix_planned: Will not fix
Fixed
48 products (1,373 components)
Red Hat Enterprise Linux Server (v. 7) · Red Hat Enterprise Linux Server Supplementary (v. 5) · Red Hat Enterprise Linux Server Supplementary (v. 6) · Red Hat Satellite 6.0 · Red Hat Enterprise Linux Desktop Supplementary (v. 6) · and others 43
Under investigation
3 products (12 components)
Red Hat Enterprise Linux 7 · Red Hat Enterprise Linux 6 · Red Hat Enterprise Linux 5
In short

SSL 3.0 has a weakness in how it handles encryption padding that allows attackers to decrypt encrypted messages if they can intercept the connection. This flaw, known as POODLE, affects older encryption systems still in use today.

Technical detail

SSL 3.0 implements nondeterministic CBC padding, enabling padding-oracle attacks where a MITM attacker can systematically decrypt ciphertext by observing padding validation responses. Exploitation requires the attacker to intercept and manipulate client-server traffic, typically by forcing protocol downgrade from TLS to SSL 3.0.

Summary generated and translated by AI from the official description.
The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N
Affected products
n/a · n/a