Vulnerability record · CVE-2014-0221 · published 5 June 2014
CVE-2014-0221: OpenSSL DTLS handshake recursion denial of service
OOpenssl · Openssl
The dtls1_get_message_fragment function in OpenSSL's d1_both.c mishandles a DTLS hello message during an invalid DTLS handshake, causing unbounded recursion and a client crash. It affects OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h, and the flaw is reachable remotely over the network.
Description
The dtls1_get_message_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h allows remote attackers to cause a denial of service (recursion and client crash) via a DTLS hello message in an invalid DTLS handshake.
AV:N/AC:M/Au:N/C:N/I:N/A:P
Automated analysis
medium priorityCVSS 2.0 rates this medium (4.3) with availability-only impact, but the very high EPSS score and broad OpenSSL deployment warrant prompt patching.
What it is
The dtls1_get_message_fragment function in OpenSSL's d1_both.c mishandles a DTLS hello message during an invalid DTLS handshake, causing unbounded recursion and a client crash. It affects OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h, and the flaw is reachable remotely over the network.
Impact
An attacker can crash a vulnerable DTLS client, causing a denial of service. There is no confidentiality or integrity impact; only availability is affected.
Attack surface
Reached over the network via a crafted DTLS hello message in an invalid DTLS handshake; no authentication is required, though the CVSS vector notes medium access complexity. No user interaction is indicated.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high (0.87892, 99.75th percentile), indicating elevated likelihood of exploitation activity.
What to do
- Upgrade OpenSSL to 0.9.8za, 1.0.0m, 1.0.1h or later, or apply the vendor patch for your distribution.
- Update dependent packages (Red Hat, Fedora, MariaDB, openSUSE/SUSE, Oracle, Juniper, IBM AIX) to their fixed errata versions.
- Disable or restrict DTLS where it is not required, and limit exposure of DTLS services to trusted networks.
- Monitor vendor advisories for backported fixes if you cannot move to a fixed upstream release.
Detection
- Monitor for crashes or abnormal termination of DTLS clients and services that use OpenSSL.
- Inspect network traffic for malformed or repeated DTLS hello messages during handshake attempts.
- Correlate host logs for OpenSSL-related crash signatures with inbound DTLS connection attempts.
- Track OpenSSL versions in use and alert on hosts still running affected releases.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
11 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2014-0221 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-0221), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.