← Vulnerability feed

Vulnerability record · CVE-2014-0224 · published 5 June 2014

CVE-2014-0224: OpenSSL ChangeCipherSpec handling flaw enables MITM session hijack

OOpenssl · Openssl

OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages. A man-in-the-middle can force use of a zero-length master key in OpenSSL-to-OpenSSL TLS communications, allowing session hijacking or disclosure of sensitive data. The flaw is known as CCS Injection.

7.4 CVSS 3.1 High EPSS 95% · top 0.1% CWE-326 · Inadequate encryption strength
7.4CVSS 3.1 base score, v2 5.8
95%EPSS exploitation probability, 30 days
NoNot in CISA KEV
16Affected product versions listed by NVD
606References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive information, via a crafted TLS handshake, aka the "CCS Injection" vulnerability.

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityCVSS 3.1 is 7.4 (HIGH) with high confidentiality and integrity impact, and EPSS is near the top of the distribution, though no KEV listing or confirmed in-the-wild exploitation is provided.

What it is

OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages. A man-in-the-middle can force use of a zero-length master key in OpenSSL-to-OpenSSL TLS communications, allowing session hijacking or disclosure of sensitive data. The flaw is known as CCS Injection.

Impact

An attacker positioned in the network path can decrypt or manipulate traffic and hijack affected TLS sessions. Both confidentiality and integrity are impacted; availability is not.

Attack surface

Reached over the network via a crafted TLS handshake; no authentication or user interaction is required, but the attacker must be able to intercept the connection (MITM position). The description scopes the key-derivation weakness to OpenSSL-to-OpenSSL communications.

Exploitation

Not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high (0.95326 probability, 0.99863 percentile), indicating strong likelihood of attempted exploitation. Reference tags are advisory-only and do not confirm in-the-wild exploitation.

What to do

  • Upgrade OpenSSL to 0.9.8za, 1.0.0m, 1.0.1h or later, or apply the vendor patch for your distribution.
  • Patch or replace dependent products listed as affected (JBoss, MariaDB, Python, Node.js, FileZilla Server, Siemens firmware, and others) using vendor advisories.
  • Disable or restrict TLS versions and cipher suites that permit the vulnerable handshake behavior where operationally possible.
  • Enforce certificate validation and avoid connecting through untrusted or unauthenticated network paths to reduce MITM exposure.
  • Inventory TLS endpoints and embedded devices that may still run unpatched OpenSSL builds.

Detection

  • Inspect TLS handshake logs for unexpected or repeated ChangeCipherSpec messages before key exchange completes.
  • Monitor for anomalous TLS session resumption or key material behavior on OpenSSL endpoints.
  • Use network IDS signatures for CCS Injection handshake patterns if available.
  • Correlate endpoint OpenSSL version data against the fixed versions to find unpatched hosts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

16 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://aix.software.ibm.com/aix/efixes/security/openssl_advisory9.asc Third Party Advisory
http://ccsinjection.lepidum.co.jp Third Party Advisory
http://dev.mysql.com/doc/relnotes/workbench/en/wb-news-6-1-7.html Third Party Advisory
http://esupport.trendmicro.com/solution/en-US/1103813.aspx Third Party Advisory
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10629 Not Applicable
http://kb.juniper.net/InfoCenter/index?page=content&id=KB29195 Not Applicable
http://kb.juniper.net/InfoCenter/index?page=content&id=KB29217 Third Party Advisory
http://linux.oracle.com/errata/ELSA-2014-1053.html Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136470.html Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136473.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00027.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00016.html Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.html Third Party Advisory
http://lists.opensuse.org/opensuse-updates/2015-02/msg00030.html Third Party Advisory
http://marc.info/?l=bugtraq&m=140266410314613&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=140317760000786&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=140369637402535&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=140386311427810&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=140389274407904&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=140389355508263&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=140431828824371&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=140448122410568&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=140482916501310&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=140491231331543&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=140499864129699&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=140544599631400&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=140604261522465&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=140621259019789&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=140672208601650&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=140752315422991&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=140784085708882&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=140794476212181&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=140852757108392&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=140852826008699&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=140870499402361&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=140904544427729&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=140983229106599&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=141025641601169&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=141147110427269&w=2 Third Party Advisory
http://marc.info/?l=bugtraq&m=141164638606214&w=2 Third Party Advisory

Track CVE-2014-0224 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.8CVE-2024-4577PHP-CGI on Windows argument injection leads to remote code executionPHP-CGI on Windows can misinterpret characters in the command line passed to Win32 API functions when certain code pages are configured, due to Windo…KEVEPSS 100%analysed9.8CVE-2021-44026Roundcube Webmail SQL injection via search parametersRoundcube Webmail before 1.3.17 and 1.4.x before 1.4.12 is prone to SQL injection through the search or search_params input. The flaw is remotely rea…KEVEPSS 70%analysed9.8CVE-2021-42013Apache HTTP Server path traversal and RCE via incomplete fixThe fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient, leaving a path traversal flaw that lets attackers map URLs to files outside…KEVEPSS 100%analysed9.8CVE-2021-41773Apache HTTP Server 2.4.49 path traversal and RCEA path normalization flaw introduced in Apache HTTP Server 2.4.49 lets attackers map URLs to files outside directories configured by Alias-like direc…KEVEPSS 100%analysed9.8CVE-2021-1870Apple WebKit logic flaw allows remote code executionA logic issue in Apple's WebKit was addressed with improved restrictions, affecting macOS Big Sur, Catalina, Mojave, iOS and iPadOS, plus WebKitGTK a…KEVEPSS 7.7%analysed9.8CVE-2021-1871Apple WebKit logic flaw allows remote code executionA logic issue in Apple's WebKit was addressed with improved restrictions. It affects macOS Big Sur, Catalina, Mojave, iOS and iPadOS, and a remote at…KEVEPSS 7.0%analysed9.8CVE-2020-16846SaltStack Salt API shell injection via crafted web requestsSaltStack Salt through 3002 is vulnerable to OS command injection when the SSH client is enabled and crafted web requests are sent to the Salt API. T…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2014-0224), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.