CVE-2014-3566

low
Published 2014-10-15 · Modified 2026-05-06
CVSS v3
3.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N
CVSS v2
4.3
VIR risk
3.4

Description

The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.

Predictions

Exploit likelihood
45%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2014-3566

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://www.openssl.org/~bodo/ssl-poodle.pdf

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://www.openssl.org/news/secadv_20141015.txt

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://technet.microsoft.com/library/security/3009008.aspx

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://support.apple.com/kb/HT6542

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://support.apple.com/kb/HT6541

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://support.apple.com/kb/HT6536

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://support.apple.com/kb/HT6535

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://support.apple.com/kb/HT6531

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://support.apple.com/kb/HT6529

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://support.apple.com/kb/HT6527

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://support.apple.com/HT205217

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://www.ubuntu.com/usn/USN-2487-1

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://www.ubuntu.com/usn/USN-2486-1

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2014-3566.html

OS impact

OSVersionStatusFixed in
suse slesaffected
debian debianbookwormfixed0
debian debianbullseyefixed0
debian debianforkyfixed0
debian debiansidfixed0
debian debiantrixiefixed0
freebsd freebsd5.1.1affected
freebsd freebsd5.1.2affected
freebsd freebsd5.1.3affected
freebsd freebsd5.1.4affected
freebsd freebsd5.2affected
freebsd freebsd5.2.1affected
freebsd freebsd5.2.2affected
freebsd freebsd6.0affected
freebsd freebsd6.0.1affected
freebsd freebsd6.0.2affected
freebsd freebsd6.0.3affected
freebsd freebsd6.0.4affected
freebsd freebsd6.0.5affected
freebsd freebsd6.0.6affected
freebsd freebsd6.1affected
freebsd freebsd6.1.1affected
freebsd freebsd6.1.2affected
freebsd freebsd6.1.3affected
freebsd freebsd6.1.4affected
freebsd freebsd6.1.5affected
debian debian7.0affected
debian debian8.0affected
macos macosaffected
suse suse11.0affected
suse suse12.0affected
suse suse12.3affected
suse suse13.1affected
redhat rhel5affected
redhat rhel6.0affected
redhat rhel7.0affected
fedora fedora19affected
fedora fedora20affected
fedora fedora21affected
freebsd freebsd5.1affected

Application impact

VendorProductVersionsFixed
novellsuse_linux_enterprise_software_development_kit11.0
novellsuse_linux_enterprise_software_development_kit12.0
opensslopenssl0.9.8
opensslopenssl0.9.8a
opensslopenssl0.9.8b
opensslopenssl0.9.8c
opensslopenssl0.9.8d
opensslopenssl0.9.8e
opensslopenssl0.9.8f
opensslopenssl0.9.8g
opensslopenssl0.9.8h
opensslopenssl0.9.8i
opensslopenssl0.9.8j
opensslopenssl0.9.8k
opensslopenssl0.9.8l
opensslopenssl0.9.8m
opensslopenssl0.9.8n
opensslopenssl0.9.8o
opensslopenssl0.9.8p
opensslopenssl0.9.8q
opensslopenssl0.9.8r
opensslopenssl0.9.8s
opensslopenssl0.9.8t
opensslopenssl0.9.8u
opensslopenssl0.9.8v
opensslopenssl0.9.8w
opensslopenssl0.9.8x
opensslopenssl0.9.8y
opensslopenssl0.9.8z
opensslopenssl0.9.8za
opensslopenssl0.9.8zb
opensslopenssl1.0.0
opensslopenssl1.0.0a
opensslopenssl1.0.0b
opensslopenssl1.0.0c
opensslopenssl1.0.0d
opensslopenssl1.0.0e
opensslopenssl1.0.0f
opensslopenssl1.0.0g
opensslopenssl1.0.0h
opensslopenssl1.0.0i
opensslopenssl1.0.0j
opensslopenssl1.0.0k
opensslopenssl1.0.0l
opensslopenssl1.0.0m
opensslopenssl1.0.0n
opensslopenssl1.0.1
opensslopenssl1.0.1a
opensslopenssl1.0.1b
opensslopenssl1.0.1c
opensslopenssl1.0.1d
opensslopenssl1.0.1e
opensslopenssl1.0.1f
opensslopenssl1.0.1g
opensslopenssl1.0.1h
opensslopenssl1.0.1i
ibmvios2.2.0.10
ibmvios2.2.0.11
ibmvios2.2.0.12
ibmvios2.2.0.13
ibmvios2.2.1.0
ibmvios2.2.1.1
ibmvios2.2.1.3
ibmvios2.2.1.4
ibmvios2.2.1.5
ibmvios2.2.1.6
ibmvios2.2.1.7
ibmvios2.2.1.8
ibmvios2.2.1.9
ibmvios2.2.2.0
ibmvios2.2.2.1
ibmvios2.2.2.2
ibmvios2.2.2.3
ibmvios2.2.2.4
ibmvios2.2.2.5
ibmvios2.2.3.0
ibmvios2.2.3.1
ibmvios2.2.3.2
ibmvios2.2.3.3
ibmvios2.2.3.4
oracledatabase11.2.0.4
oracledatabase12.1.0.2

References

CWEs

CWE-310

Verify integrity in audit chain (admin only). AS-IS.