Cryptographic Issues
CVE-2014-3566
Summary
The SSL protocol 3.0, as used in OpenSSL through 0.9.8zb, 1.0.0 through 1.0.0n, 1.0.1 through 1.0.1i and 1.0.2-beta1 through 1.0.2-beta3, and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.
- HIGH
- NETWORK
- NONE
- CHANGED
- REQUIRED
- NONE
- LOW
- NONE
CWE-310 - Cryptographic Issues
Cryptographic issues is a category of weaknesses related to the design and implementation of the confidentiality and integrity of data. If not addressed, the weaknesses in this category can lead to data quality degradation.
References
Advisory Timeline
- Published