Vulnerability record · CVE-2014-0224 · published 5 June 2014
CVE-2014-0224: OpenSSL ChangeCipherSpec handling flaw enables MITM session hijack
OOpenssl · Openssl
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages. A man-in-the-middle can force use of a zero-length master key in OpenSSL-to-OpenSSL TLS communications, allowing session hijacking or disclosure of sensitive data. The flaw is known as CCS Injection.
Description
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive information, via a crafted TLS handshake, aka the "CCS Injection" vulnerability.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Automated analysis
high priorityCVSS 3.1 is 7.4 (HIGH) with high confidentiality and integrity impact, and EPSS is near the top of the distribution, though no KEV listing or confirmed in-the-wild exploitation is provided.
What it is
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages. A man-in-the-middle can force use of a zero-length master key in OpenSSL-to-OpenSSL TLS communications, allowing session hijacking or disclosure of sensitive data. The flaw is known as CCS Injection.
Impact
An attacker positioned in the network path can decrypt or manipulate traffic and hijack affected TLS sessions. Both confidentiality and integrity are impacted; availability is not.
Attack surface
Reached over the network via a crafted TLS handshake; no authentication or user interaction is required, but the attacker must be able to intercept the connection (MITM position). The description scopes the key-derivation weakness to OpenSSL-to-OpenSSL communications.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high (0.95326 probability, 0.99863 percentile), indicating strong likelihood of attempted exploitation. Reference tags are advisory-only and do not confirm in-the-wild exploitation.
What to do
- Upgrade OpenSSL to 0.9.8za, 1.0.0m, 1.0.1h or later, or apply the vendor patch for your distribution.
- Patch or replace dependent products listed as affected (JBoss, MariaDB, Python, Node.js, FileZilla Server, Siemens firmware, and others) using vendor advisories.
- Disable or restrict TLS versions and cipher suites that permit the vulnerable handshake behavior where operationally possible.
- Enforce certificate validation and avoid connecting through untrusted or unauthenticated network paths to reduce MITM exposure.
- Inventory TLS endpoints and embedded devices that may still run unpatched OpenSSL builds.
Detection
- Inspect TLS handshake logs for unexpected or repeated ChangeCipherSpec messages before key exchange completes.
- Monitor for anomalous TLS session resumption or key material behavior on OpenSSL endpoints.
- Use network IDS signatures for CCS Injection handshake patterns if available.
- Correlate endpoint OpenSSL version data against the fixed versions to find unpatched hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
16 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2014-0224 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-0224), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.