OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive information, via a crafted TLS handshake, aka the "CCS Injection" vulnerability.
CVSS Details
- CVSS 3.1 Base Score: 7.4
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade openssl | Aug 30, 2017 | Jun 5, 2014 |
| Apple Osx Note | — | Upgrade macOS to the latest versionApply OS X security update 2014-004 | Aug 28, 2015 | Jun 5, 2014 |
| Apple Osx Openssl | — | Upgrade macOS to the latest versionApply OS X security update 2014-004 | Sep 22, 2014 | Jun 5, 2014 |
| Centos_linux | — | Upgrade openssl-perlUpgrade openssl-develUpgrade openssl098eUpgrade openssl-staticUpgrade opensslUpgrade openssl097a | Dec 1, 2016 | Jun 5, 2014 |
| Debian | — | Upgrade openssl | Jul 30, 2024 | Jun 5, 2014 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Oct 15, 2015 |
| Freebsd | — | Upgrade mingw32-opensslUpgrade opensslUpgrade FreeBSD | Dec 10, 2025 | Jun 5, 2014 |
| Gentoo Linux | — | Upgrade dev-libs/openssl. | Oct 30, 2017 | Jun 5, 2014 |
| Google Chrome | — | Upgrade to the latest version of Google Chrome | Sep 9, 2022 | Jun 5, 2014 |
| Hpsim | — | Upgrade to the latest version of HP Systems Insight Manager | Oct 13, 2015 | Jun 5, 2014 |
| Hpsmh | — | Upgrade to the latest version of HP System Management Homepage | Oct 13, 2015 | Jun 5, 2014 |
| Hpux | — | Update openssl.OPENSSL-MIS to the latest versionUpdate openssl.OPENSSL-PVT to the latest versionUpdate openssl.OPENSSL-SRC to the latest versionUpdate openssl.OPENSSL-DOC to the latest versionUpdate openssl.OPENSSL-RUN to the latest versionUpdate openssl.OPENSSL-MAN to the latest versionUpdate openssl.OPENSSL-CER to the latest versionUpdate openssl.OPENSSL-CONF to the latest versionUpdate openssl.OPENSSL-LIB to the latest versionUpdate openssl.OPENSSL-PRNG to the latest versionUpdate openssl.OPENSSL-INC to the latest version | Aug 11, 2017 | Jun 5, 2014 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | Jun 5, 2014 | Jun 5, 2014 |
| Huawei Vrp | — | Contact Huawei TAC to request the upgrades | May 28, 2026 | Jun 13, 2014 |
| Ibm Aix | — | Apply the fix or workaround for openssl_advisory9 | Nov 30, 2017 | Jun 5, 2014 |
| Mariadb Mariadb | — | Upgrade MariaDB to the latest version | Mar 4, 2025 | Jun 5, 2014 |
| Oracle Solaris | — | Upgrade library/security/openssl/openssl-fips-140 to version 1.2-0.175.1.21.0.2.0 on Solaris 11.1Upgrade library/security/openssl to version 1.0.0.13-0.175.1.21.0.2.0 on Solaris 11.1 | May 29, 2017 | Jun 5, 2014 |
| Oracle_linux | — | Upgrade openssl-staticUpgrade openssl-libsUpgrade openssl-develUpgrade opensslUpgrade openssl-perlUpgrade openssl098eUpgrade openssl097a | Mar 22, 2016 | Jun 5, 2014 |
| Panos | — | Update PAN-OS 5.0 to the latest workaround for your deviceUpdate PAN-OS 5.1 to the latest workaround for your deviceUpdate PAN-OS 6.0 to the latest workaround for your device | Oct 12, 2016 | Jun 5, 2014 |
| Pulse Secure Pulse Connect Secure | — | Update Pulse Connect Secure to version 8.0R4.1Update Pulse Connect Secure to version 7.1R19.1Update Pulse Connect Secure to version 7.4R11.1 | Oct 28, 2020 | Jun 5, 2014 |
| Red Hat Jboss Eap | — | Upgrade Red Hat JBoss EAP to the latest version | Sep 19, 2024 | Jun 5, 2014 |
| Red_hat Jboss_eap | — | — | Nov 14, 2019 | Jun 5, 2014 |
| Suse | — | Upgrade mariadb-clientUpgrade libmysqlclient_r15Upgrade npm8Upgrade libopenssl1_1-hmacUpgrade mozilla-nssUpgrade mozilla-nspr-develUpgrade mariadbUpgrade compat-openssl097gUpgrade firefox-gtk3-immodule-ximUpgrade libopenssl0_9_8-hmac-32bitUpgrade libfirefox-gmodule-2_0-0Upgrade mozillafirefox-translations-commonUpgrade firefox-libcairo2Upgrade firefox-gtk3-immodule-multipressUpgrade firefox-libffi4Upgrade libmysql55client_r18-32bitUpgrade mariadb-errormessagesUpgrade firefox-libharfbuzz0Upgrade libopenssl1_0_0-x86Upgrade libopenssl1_1-hmac-32bitUpgrade openssl-1_1Upgrade libopenssl1_1Upgrade mozilla-nspr-32bitUpgrade firefox-gtk3-toolsUpgrade libmysqlclient18-32bitUpgrade libmysqlclient-develUpgrade openssl1Upgrade libopenssl0_9_8-hmacUpgrade libopenssl-1_1-develUpgrade firefox-libgtk-3-0Upgrade libmysqlclient_r18Upgrade firefox-gdk-pixbuf-query-loadersUpgrade firefox-gtk3-branding-upstreamUpgrade mozillafirefox-branding-sledUpgrade firefox-gio-branding-upstreamUpgrade libfreebl3Upgrade compat-openssl097g-32bitUpgrade firefox-libffi7Upgrade libfirefox-gthread-2_0-0Upgrade opensslUpgrade libmysql55client18-32bitUpgrade firefox-libcairo-gobject2Upgrade mariadb-toolsUpgrade openssl-1_0_0-docUpgrade virtualbox-guest-x11Upgrade libmysql55client18-x86Upgrade firefox-gtk3-immodules-tigrignaUpgrade firefox-glib2-langUpgrade libmysqlclient15-x86Upgrade libmysql55client_r18-x86Upgrade nodejs8-docsUpgrade mariadb-100-errormessagesUpgrade libopenssl1_0_0Upgrade libfirefox-glib-2_0-0Upgrade mysqlUpgrade libsoftokn3-32bitUpgrade openssl1-docUpgrade libfirefox-gobject-2_0-0Upgrade firefox-gtk3-immodule-amharicUpgrade mozilla-nss-develUpgrade openssl-1_0_0Upgrade mozillafirefox-translations-otherUpgrade libopenssl-develUpgrade libmysqlclient15Upgrade firefox-atk-langUpgrade libmysql55client18Upgrade virtualbox-guest-kmp-defaultUpgrade libopenssl-1_0_0-develUpgrade libopenssl0_9_8-x86Upgrade libopenssl0_9_8-32bitUpgrade libsoftokn3Upgrade firefox-gdk-pixbuf-langUpgrade mozilla-nss-certs-32bitUpgrade firefox-gtk3-immodule-inuktitutUpgrade nodejs8-develUpgrade libmysqld18Upgrade mozillafirefoxUpgrade firefox-libatk-1_0-0Upgrade libmysqlclient18Upgrade libopenssl1_1-32bitUpgrade nodejs8Upgrade firefox-libgdk_pixbuf-2_0-0Upgrade libmysqlclient_r18-32bitUpgrade mysql-clientUpgrade libopenssl-1_1-devel-32bitUpgrade virtualbox-guest-toolsUpgrade libmysqlclient_r15-x86Upgrade firefox-gtk3-dataUpgrade libmysqld-develUpgrade firefox-gtk3-langUpgrade firefox-libpango-1_0-0Upgrade mozilla-nss-toolsUpgrade libmysqlclient_r15-32bitUpgrade libopenssl0_9_8Upgrade mozilla-nss-certsUpgrade mozilla-nsprUpgrade libopenssl1_0_0-32bitUpgrade openssl-docUpgrade libmysqlclient15-32bitUpgrade mozilla-nss-32bitUpgrade firefox-glib2-toolsUpgrade firefox-gtk3-immodule-vietnameseUpgrade firefox-gdk-pixbuf-thumbnailerUpgrade libmysql55client_r18Upgrade libopenssl1_0_0-hmacUpgrade firefox-gtk3-immodule-thaiUpgrade libopenssl1_0_0-hmac-32bitUpgrade libfirefox-gio-2_0-0Upgrade libopenssl1-develUpgrade libfreebl3-32bitUpgrade mysql-tools | Dec 18, 2015 | Jun 5, 2014 |
| Ubuntu | — | Upgrade libssl0.9.8Upgrade libssl1.0.0 | Nov 8, 2024 | Jun 5, 2014 |
| Vmsa 2014 0006 | — | Upgrade VMware ESXi 5.5 to build number 1881737Upgrade VMware ESXi 5.1 to build number 1900470Upgrade VMware ESXi 5.0 to build number 1918656 | Jun 19, 2014 | Jun 5, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub