Vulnerability record · CVE-2014-3512 · published 13 August 2014
CVE-2014-3512: OpenSSL SRP buffer overflows via invalid g, A, or B parameters
OOpenssl · Openssl
OpenSSL 1.0.1 before 1.0.1i contains multiple buffer overflows in the SRP implementation in crypto/srp/srp_lib.c. Invalid SRP g, A, or B parameters can overflow buffers, crashing the application or possibly causing other unspecified impact. The flaw matters because SRP is a network-reachable TLS authentication path in affected OpenSSL builds.
Description
Multiple buffer overflows in crypto/srp/srp_lib.c in the SRP implementation in OpenSSL 1.0.1 before 1.0.1i allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via an invalid SRP (1) g, (2) A, or (3) B parameter.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityNetwork-reachable, unauthenticated buffer overflow in a widely deployed library, with high EPSS despite no confirmed exploitation in this record.
What it is
OpenSSL 1.0.1 before 1.0.1i contains multiple buffer overflows in the SRP implementation in crypto/srp/srp_lib.c. Invalid SRP g, A, or B parameters can overflow buffers, crashing the application or possibly causing other unspecified impact. The flaw matters because SRP is a network-reachable TLS authentication path in affected OpenSSL builds.
Impact
A remote attacker can crash the application (denial of service) and possibly achieve unspecified further impact, though the record does not detail code execution or data compromise. CVSS 2.0 rates confidentiality, integrity and availability impact as partial.
Attack surface
Reachable over the network (AV:N) with no authentication (Au:N) and low complexity (AC:L), via SRP parameter handling in OpenSSL. No user interaction is indicated by the vector or description.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented. EPSS is high (0.68979, 99.3rd percentile), but the references carry no exploit tags, so active exploitation is not confirmed by this record.
What to do
- Upgrade OpenSSL to 1.0.1i or later, or apply the vendor patch for your distribution.
- If SRP is not required, disable or avoid SRP cipher suites and SRP-based authentication.
- Apply the referenced vendor advisories for NetBSD, IBM AIX, SUSE, Gentoo and F5 products that bundle affected OpenSSL.
- Track OpenSSL versions in embedded and appliance products, which often lag upstream fixes.
Detection
- Monitor for TLS handshakes using SRP cipher suites and correlate with crashes or abnormal process termination.
- Alert on repeated malformed or invalid SRP parameter values (g, A, B) reaching OpenSSL-based services.
- Inventory OpenSSL versions across hosts and flag any still below 1.0.1i.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2014-3512 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-3512), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.