Shortened for this page: references: 10 of 257 shown; configurations: 10 of 18 shown; configurations[].nodes[].cpe_match: first 10 items; enrichment.cpe: first 10 items; enrichment.cpe[].cpe_names: first 10 items; enrichment.cpe[].affected_versions: first 10 items
{
"id": "CVE-2014-0160",
"source_identifier": "user@redhat.com",
"published": "2014-04-07T22:55:03Z",
"last_modified": "2026-06-17T00:02:24Z",
"status": "Analyzed",
"evaluator_comment": null,
"evaluator_solution": null,
"evaluator_impact": "CVSS V2 scoring evaluates the impact of the vulnerability on the host where the vulnerability is located. When evaluating the impact of this vulnerability to your organization, take into account the nature of the data that is being protected and act according to your organization’s risk acceptance. While CVE-2014-0160 does not allow unrestricted access to memory on the targeted host, a successful exploit does leak information from memory locations which have the potential to contain particularly sensitive information, e.g., cryptographic keys and passwords. Theft of this information could enable other attacks on the information system, the impact of which would depend on the sensitivity of the data and functions of that system.",
"cisa_exploit_add": "2022-05-04",
"cisa_action_due": "2022-05-25",
"cisa_required_action": "Apply updates per vendor instructions.",
"cisa_vulnerability_name": "OpenSSL Information Disclosure Vulnerability",
"descriptions": [
{
"lang": "en",
"value": "The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug."
},
{
"lang": "es",
"value": "Las implementaciones de (1) TLS y (2) DTLS en OpenSSL 1.0.1 en versiones anteriores a 1.0.1g no manejan adecuadamente paquetes Heartbeat Extension, lo que permite a atacantes remotos obtener información sensible desde la memoria de proceso a través de paquetes manipulados que desencadenan una sobrelectura del buffer, según lo demostrado mediante la lectura de claves privadas, relacionado con d1_both.c y t1_lib.c, también conocido como bug Heartbleed."
}
],
"references": [
{
"url": "http://advisories.mageia.org/MGASA-2014-0165.html",
"source": "user@redhat.com",
"tags": [
"Third Party Advisory"
]
},
{
"url": "http://blog.fox-it.com/2014/04/08/openssl-heartbleed-bug-live-blog/",
"source": "user@redhat.com",
"tags": [
"Issue Tracking",
"Third Party Advisory"
]
},
{
"url": "http://cogentdatahub.com/ReleaseNotes.html",
"source": "user@redhat.com",
"tags": [
"Release Notes"
]
},
{
"url": "http://download.schneider-electric.com/files?p_Doc_Ref=SEVD%202014-119-01",
"source": "user@redhat.com",
"tags": [
"Broken Link"
]
},
{
"url": "http://git.openssl.org/gitweb/?p=openssl.git%3Ba=commit%3Bh=96db9023b881d7cd9f379b0c154650d6c108e9a3",
"source": "user@redhat.com",
"tags": [
"Broken Link"
]
},
{
"url": "http://heartbleed.com/",
"source": "user@redhat.com",
"tags": [
"Third Party Advisory"
]
},
{
"url": "http://lists.fedoraproject.org/pipermail/package-announce/2014-April/131221.html",
"source": "user@redhat.com",
"tags": [
"Broken Link",
"Third Party Advisory"
]
},
{
"url": "http://lists.fedoraproject.org/pipermail/package-announce/2014-April/131291.html",
"source": "user@redhat.com",
"tags": [
"Broken Link",
"Third Party Advisory"
]
},
{
"url": "http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136473.html",
"source": "user@redhat.com",
"tags": [
"Mailing List",
"Third Party Advisory"
]
},
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2014-04/msg00004.html",
"source": "user@redhat.com",
"tags": [
"Mailing List",
"Third Party Advisory"
]
}
],
"metrics": {
"cvss_metric_v40": null,
"cvss_metric_v31": [
{
"source": "user@nist.gov",
"type": "Primary",
"cvss_data": {
"version": "3.1",
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"attack_vector": "NETWORK",
"attack_complexity": "LOW",
"privileges_required": "NONE",
"user_interaction": "NONE",
"scope": "UNCHANGED",
"confidentiality_impact": "HIGH",
"integrity_impact": "NONE",
"availability_impact": "NONE",
"base_score": 7.5,
"base_severity": "HIGH",
"exploit_code_maturity": null,
"remediation_level": null,
"report_confidence": null,
"temporal_score": null,
"temporal_severity": null,
"confidentiality_requirement": null,
"integrity_requirement": null,
"availability_requirement": null,
"modified_attack_vector": null,
"modified_attack_complexity": null,
"modified_privileges_required": null,
"modified_user_interaction": null,
"modified_scope": null,
"modified_confidentiality_impact": null,
"modified_integrity_impact": null,
"modified_availability_impact": null,
"environmental_score": null,
"environmental_severity": null
},
"exploitability_score": 3.9,
"impact_score": 3.6
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary",
"cvss_data": {
"version": "3.1",
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"attack_vector": "NETWORK",
"attack_complexity": "LOW",
"privileges_required": "NONE",
"user_interaction": "NONE",
"scope": "UNCHANGED",
"confidentiality_impact": "HIGH",
"integrity_impact": "NONE",
"availability_impact": "NONE",
"base_score": 7.5,
"base_severity": "HIGH",
"exploit_code_maturity": null,
"remediation_level": null,
"report_confidence": null,
"temporal_score": null,
"temporal_severity": null,
"confidentiality_requirement": null,
"integrity_requirement": null,
"availability_requirement": null,
"modified_attack_vector": null,
"modified_attack_complexity": null,
"modified_privileges_required": null,
"modified_user_interaction": null,
"modified_scope": null,
"modified_confidentiality_impact": null,
"modified_integrity_impact": null,
"modified_availability_impact": null,
"environmental_score": null,
"environmental_severity": null
},
"exploitability_score": 3.9,
"impact_score": 3.6
}
],
"cvss_metric_v30": null,
"cvss_metric_v2": [
{
"source": "user@nist.gov",
"type": "Primary",
"cvss_data": {
"version": "2.0",
"vector_string": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"access_vector": "NETWORK",
"access_complexity": "LOW",
"authentication": "NONE",
"confidentiality_impact": "PARTIAL",
"integrity_impact": "NONE",
"availability_impact": "NONE",
"base_score": 5.0,
"exploitability": null,
"remediation_level": null,
"report_confidence": null,
"temporal_score": null,
"collateral_damage_potential": null,
"target_distribution": null,
"confidentiality_requirement": null,
"integrity_requirement": null,
"availability_requirement": null,
"environmental_score": null
},
"base_severity": "MEDIUM",
"exploitability_score": 10.0,
"impact_score": 2.9,
"ac_insuf_info": false,
"obtain_all_privilege": false,
"obtain_user_privilege": false,
"obtain_other_privilege": false,
"user_interaction_required": false
}
]
},
"weaknesses": [
{
"source": "user@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-125"
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-125"
}
]
}
],
"configurations": [
{
"operator": null,
"negate": null,
"nodes": [
{
"operator": "OR",
"negate": false,
"cpe_match": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*",
"match_criteria_id": "9EE79AC6-5484-4A53-8333-373DAD1B5649",
"version_start_including": "1.0.1",
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": "1.0.1g"
}
]
}
]
},
{
"operator": null,
"negate": null,
"nodes": [
{
"operator": "OR",
"negate": false,
"cpe_match": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:filezilla-project:filezilla_server:*:*:*:*:*:*:*:*",
"match_criteria_id": "3F09BC00-9D25-4C39-B705-A5A29F630517",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": "0.9.44"
}
]
}
]
},
{
"operator": "AND",
"negate": null,
"nodes": [
{
"operator": "OR",
"negate": false,
"cpe_match": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:siemens:application_processing_engine_firmware:2.0:*:*:*:*:*:*:*",
"match_criteria_id": "119DBCCC-439E-4148-9E11-CE8038066811",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
}
]
},
{
"operator": "OR",
"negate": false,
"cpe_match": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:siemens:application_processing_engine:-:*:*:*:*:*:*:*",
"match_criteria_id": "AE6A8466-8A69-491B-8DAB-877A6C2F6660",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
}
]
}
]
},
{
"operator": "AND",
"negate": null,
"nodes": [
{
"operator": "OR",
"negate": false,
"cpe_match": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:siemens:cp_1543-1_firmware:1.1:*:*:*:*:*:*:*",
"match_criteria_id": "B60287DD-E302-4F8C-833F-E8BE94BDB8D5",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
}
]
},
{
"operator": "OR",
"negate": false,
"cpe_match": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:siemens:cp_1543-1:-:*:*:*:*:*:*:*",
"match_criteria_id": "F703FF33-882F-4CB5-9CA0-8FAE670B2AEF",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
}
]
}
]
},
{
"operator": "AND",
"negate": null,
"nodes": [
{
"operator": "OR",
"negate": false,
"cpe_match": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:siemens:simatic_s7-1500_firmware:1.5:*:*:*:*:*:*:*",
"match_criteria_id": "92646048-3383-4F12-ABCA-8346D9837C2C",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
}
]
},
{
"operator": "OR",
"negate": false,
"cpe_match": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:siemens:simatic_s7-1500:-:*:*:*:*:*:*:*",
"match_criteria_id": "30DDEA9B-E1BF-4572-8E12-D13C54603E77",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
}
]
}
]
},
{
"operator": "AND",
"negate": null,
"nodes": [
{
"operator": "OR",
"negate": false,
"cpe_match": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:siemens:simatic_s7-1500t_firmware:1.5:*:*:*:*:*:*:*",
"match_criteria_id": "80CEA1F3-B820-4D36-B879-7D55F3B95002",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
}
]
},
{
"operator": "OR",
"negate": false,
"cpe_match": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:siemens:simatic_s7-1500t:-:*:*:*:*:*:*:*",
"match_criteria_id": "741B2C38-174C-49DF-98D8-F7D6F49D1CE5",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
}
]
}
]
},
{
"operator": null,
"negate": null,
"nodes": [
{
"operator": "OR",
"negate": false,
"cpe_match": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:siemens:elan-8.2:*:*:*:*:*:*:*:*",
"match_criteria_id": "B77B3ED9-1841-449E-B3B2-F53E73254314",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": "8.3.3"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:siemens:wincc_open_architecture:3.12:*:*:*:*:*:*:*",
"match_criteria_id": "B42FE7D9-673C-4FF3-924B-FC21DF06F769",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
}
]
}
]
},
{
"operator": "AND",
"negate": null,
"nodes": [
{
"operator": "OR",
"negate": false,
"cpe_match": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:intellian:v100_firmware:1.20:*:*:*:*:*:*:*",
"match_criteria_id": "A3F2BCF2-2D0C-44AB-AE21-FBC7F04D099A",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:o:intellian:v100_firmware:1.21:*:*:*:*:*:*:*",
"match_criteria_id": "B46DDC44-A1B4-4DF8-8AD5-FD235F1C2D54",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:o:intellian:v100_firmware:1.24:*:*:*:*:*:*:*",
"match_criteria_id": "82BF6806-3E91-4B22-B53D-13F4CD19F757",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
}
]
},
{
"operator": "OR",
"negate": false,
"cpe_match": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:intellian:v100:-:*:*:*:*:*:*:*",
"match_criteria_id": "DF9C2817-7F10-4369-A106-68DF9369B454",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
}
]
}
]
},
{
"operator": "AND",
"negate": null,
"nodes": [
{
"operator": "OR",
"negate": false,
"cpe_match": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:intellian:v60_firmware:1.15:*:*:*:*:*:*:*",
"match_criteria_id": "9079EBFD-B901-4077-AD4B-A8B034BDDEA1",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:o:intellian:v60_firmware:1.25:*:*:*:*:*:*:*",
"match_criteria_id": "CFC20C7E-E264-4892-AA43-E289207935EE",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
}
]
},
{
"operator": "OR",
"negate": false,
"cpe_match": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:intellian:v60:-:*:*:*:*:*:*:*",
"match_criteria_id": "BD513662-1089-4BF8-A0F8-9BE5CBF937BE",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
}
]
}
]
},
{
"operator": null,
"negate": null,
"nodes": [
{
"operator": "OR",
"negate": false,
"cpe_match": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:mitel:micollab:6.0:*:*:*:*:*:*:*",
"match_criteria_id": "03433A5D-632E-47A5-871A-5859C80CB038",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:mitel:micollab:7.0:*:*:*:*:*:*:*",
"match_criteria_id": "2B28F2FB-F263-4B2E-A4C7-951A474FD7F9",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:mitel:micollab:7.1:*:*:*:*:*:*:*",
"match_criteria_id": "DC89913A-F419-43E8-B846-D7AA769EA898",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:mitel:micollab:7.2:*:*:*:*:*:*:*",
"match_criteria_id": "9C5C14AB-2C97-406E-98B5-0BDC8B0AFEA1",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:mitel:micollab:7.3:*:*:*:*:*:*:*",
"match_criteria_id": "C08973EF-E86A-46D7-9CF6-4374F2789ED1",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:mitel:micollab:7.3.0.104:*:*:*:*:*:*:*",
"match_criteria_id": "F2317158-3EE7-4894-ADC0-109E0D94DA0A",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:mitel:mivoice:1.1.2.5:*:*:*:*:lync:*:*",
"match_criteria_id": "501B4ED7-0A26-430A-91A2-29099D3CF493",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:mitel:mivoice:1.1.3.3:*:*:*:*:skype_for_business:*:*",
"match_criteria_id": "A93F15B3-1341-446F-85D0-E1842EA1F42C",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:mitel:mivoice:1.2.0.11:*:*:*:*:skype_for_business:*:*",
"match_criteria_id": "37A5858D-8DE8-4865-A803-7D8A9D4EA306",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:mitel:mivoice:1.3.2.2:*:*:*:*:skype_for_business:*:*",
"match_criteria_id": "32B33A4D-1E37-4EAA-AE25-7DA399D50046",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
}
]
}
]
}
],
"vendor_comments": null,
"enrichment": {
"cpe": [
{
"criteria": "cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*",
"vendor": "openssl",
"product": "openssl",
"product_type": "a",
"vulnerable": true,
"version_start_including": "1.0.1",
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": "1.0.1g",
"affected_versions_first": "1.0.1d",
"affected_versions_last": "1.0.1",
"affected_versions": [
"1.0.1d",
"1.0.1e",
"1.0.1f",
"1.0.1a",
"1.0.1b",
"1.0.1c",
"1.0.1"
],
"cpe_names": [
{
"cpe_name": "cpe:2.3:a:openssl:openssl:1.0.1:*:*:*:*:*:*:*",
"deprecated": true
},
{
"cpe_name": "cpe:2.3:a:openssl:openssl:1.0.1:-:*:*:*:*:*:*",
"deprecated": false
},
{
"cpe_name": "cpe:2.3:a:openssl:openssl:1.0.1:beta1:*:*:*:*:*:*",
"deprecated": false
},
{
"cpe_name": "cpe:2.3:a:openssl:openssl:1.0.1:beta2:*:*:*:*:*:*",
"deprecated": false
},
{
"cpe_name": "cpe:2.3:a:openssl:openssl:1.0.1:beta3:*:*:*:*:*:*",
"deprecated": false
},
{
"cpe_name": "cpe:2.3:a:openssl:openssl:1.0.1a:*:*:*:*:*:*:*",
"deprecated": false
},
{
"cpe_name": "cpe:2.3:a:openssl:openssl:1.0.1b:*:*:*:*:*:*:*",
"deprecated": false
},
{
"cpe_name": "cpe:2.3:a:openssl:openssl:1.0.1c:*:*:*:*:*:*:*",
"deprecated": false
},
{
"cpe_name": "cpe:2.3:a:openssl:openssl:1.0.1d:*:*:*:*:*:*:*",
"deprecated": false
},
{
"cpe_name": "cpe:2.3:a:openssl:openssl:1.0.1e:*:*:*:*:*:*:*",
"deprecated": false
}
]
},
{
"criteria": "cpe:2.3:a:filezilla-project:filezilla_server:*:*:*:*:*:*:*:*",
"vendor": "filezilla-project",
"product": "filezilla_server",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": "0.9.44",
"affected_versions_first": "0.9.6",
"affected_versions_last": "0.9.43",
"affected_versions": [
"0.9.6",
"0.9.21",
"0.9.22",
"0.9.26",
"0.9.27",
"0.9.28",
"0.9.29",
"0.9.30",
"0.9.31",
"0.9.32"
],
"cpe_names": [
{
"cpe_name": "cpe:2.3:a:filezilla-project:filezilla_server:0.9.6:*:*:*:*:*:*:*",
"deprecated": false
},
{
"cpe_name": "cpe:2.3:a:filezilla-project:filezilla_server:0.9.21:*:*:*:*:*:*:*",
"deprecated": false
},
{
"cpe_name": "cpe:2.3:a:filezilla-project:filezilla_server:0.9.22:*:*:*:*:*:*:*",
"deprecated": false
},
{
"cpe_name": "cpe:2.3:a:filezilla-project:filezilla_server:0.9.26:*:*:*:*:*:*:*",
"deprecated": false
},
{
"cpe_name": "cpe:2.3:a:filezilla-project:filezilla_server:0.9.27:*:*:*:*:*:*:*",
"deprecated": false
},
{
"cpe_name": "cpe:2.3:a:filezilla-project:filezilla_server:0.9.28:*:*:*:*:*:*:*",
"deprecated": false
},
{
"cpe_name": "cpe:2.3:a:filezilla-project:filezilla_server:0.9.29:*:*:*:*:*:*:*",
"deprecated": false
},
{
"cpe_name": "cpe:2.3:a:filezilla-project:filezilla_server:0.9.30:*:*:*:*:*:*:*",
"deprecated": false
},
{
"cpe_name": "cpe:2.3:a:filezilla-project:filezilla_server:0.9.31:*:*:*:*:*:*:*",
"deprecated": false
},
{
"cpe_name": "cpe:2.3:a:filezilla-project:filezilla_server:0.9.32:*:*:*:*:*:*:*",
"deprecated": false
}
]
},
{
"criteria": "cpe:2.3:o:siemens:application_processing_engine_firmware:2.0:*:*:*:*:*:*:*",
"vendor": "siemens",
"product": "application_processing_engine_firmware",
"product_type": "o",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "2.0",
"affected_versions_last": "2.0",
"affected_versions": [
"2.0"
],
"cpe_names": [
{
"cpe_name": "cpe:2.3:o:siemens:application_processing_engine_firmware:2.0:*:*:*:*:*:*:*",
"deprecated": false
}
]
},
{
"criteria": "cpe:2.3:h:siemens:application_processing_engine:-:*:*:*:*:*:*:*",
"vendor": "siemens",
"product": "application_processing_engine",
"product_type": "h",
"vulnerable": false,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": null,
"affected_versions_last": null,
"affected_versions": [
"-"
],
"cpe_names": [
{
"cpe_name": "cpe:2.3:h:siemens:application_processing_engine:-:*:*:*:*:*:*:*",
"deprecated": false
}
]
},
{
"criteria": "cpe:2.3:o:siemens:cp_1543-1_firmware:1.1:*:*:*:*:*:*:*",
"vendor": "siemens",
"product": "cp_1543-1_firmware",
"product_type": "o",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "1.1",
"affected_versions_last": "1.1",
"affected_versions": [
"1.1"
],
"cpe_names": [
{
"cpe_name": "cpe:2.3:o:siemens:cp_1543-1_firmware:1.1:*:*:*:*:*:*:*",
"deprecated": false
}
]
},
{
"criteria": "cpe:2.3:h:siemens:cp_1543-1:-:*:*:*:*:*:*:*",
"vendor": "siemens",
"product": "cp_1543-1",
"product_type": "h",
"vulnerable": false,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": null,
"affected_versions_last": null,
"affected_versions": [
"-"
],
"cpe_names": [
{
"cpe_name": "cpe:2.3:h:siemens:cp_1543-1:-:*:*:*:*:*:*:*",
"deprecated": false
}
]
},
{
"criteria": "cpe:2.3:o:siemens:simatic_s7-1500_firmware:1.5:*:*:*:*:*:*:*",
"vendor": "siemens",
"product": "simatic_s7-1500_firmware",
"product_type": "o",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "1.5",
"affected_versions_last": "1.5",
"affected_versions": [
"1.5"
],
"cpe_names": [
{
"cpe_name": "cpe:2.3:o:siemens:simatic_s7-1500_firmware:1.5:*:*:*:*:*:*:*",
"deprecated": false
}
]
},
{
"criteria": "cpe:2.3:h:siemens:simatic_s7-1500:-:*:*:*:*:*:*:*",
"vendor": "siemens",
"product": "simatic_s7-1500",
"product_type": "h",
"vulnerable": false,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": null,
"affected_versions_last": null,
"affected_versions": [
"-"
],
"cpe_names": [
{
"cpe_name": "cpe:2.3:h:siemens:simatic_s7-1500:-:*:*:*:*:*:*:*",
"deprecated": false
}
]
},
{
"criteria": "cpe:2.3:o:siemens:simatic_s7-1500t_firmware:1.5:*:*:*:*:*:*:*",
"vendor": "siemens",
"product": "simatic_s7-1500t_firmware",
"product_type": "o",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "1.5",
"affected_versions_last": "1.5",
"affected_versions": [
"1.5"
],
"cpe_names": [
{
"cpe_name": "cpe:2.3:o:siemens:simatic_s7-1500t_firmware:1.5:*:*:*:*:*:*:*",
"deprecated": false
}
]
},
{
"criteria": "cpe:2.3:h:siemens:simatic_s7-1500t:-:*:*:*:*:*:*:*",
"vendor": "siemens",
"product": "simatic_s7-1500t",
"product_type": "h",
"vulnerable": false,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": null,
"affected_versions_last": null,
"affected_versions": [
"-"
],
"cpe_names": [
{
"cpe_name": "cpe:2.3:h:siemens:simatic_s7-1500t:-:*:*:*:*:*:*:*",
"deprecated": false
}
]
}
],
"cwe": [
{
"id": 125,
"owasptop10_2021": null,
"name": "Out-of-bounds Read",
"description": "The product reads data past the end, or before the beginning, of the intended buffer.",
"capec_id": [
540
],
"scope": [
"Availability",
"Confidentiality",
"Other"
],
"impact": [
"Bypass Protection Mechanism",
"DoS: Crash, Exit, or Restart",
"Read Memory",
"Varies by Context"
],
"detection_method": [
"Automated Dynamic Analysis",
"Automated Static Analysis",
"Fuzzing"
]
}
],
"epss_score": {
"epss": 0.99999,
"percentile": 0.99997,
"date": "2026-09-23"
},
"cisa_kev": {
"vendor_project": "OpenSSL",
"product": "OpenSSL",
"vulnerability_name": "OpenSSL Information Disclosure Vulnerability",
"date_added": "2022-05-04",
"short_description": "The TLS and DTLS implementations in OpenSSL do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information.",
"required_action": "Apply updates per vendor instructions.",
"due_date": "2022-05-25",
"known_ransomware_campaign_use": "Unknown",
"notes": "https://nvd.nist.gov/vuln/detail/CVE-2014-0160"
},
"vdeep_metric": {
"available_versions": [
"3.1",
"2.0"
],
"source": "user@nist.gov",
"type": "Primary",
"cvss_data": {
"version": "3.1",
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"attack_vector": "NETWORK",
"attack_complexity": "LOW",
"attack_requirements": null,
"privileges_required": "NONE",
"user_interaction": "NONE",
"vulnerable_system_confidentiality": "HIGH",
"vulnerable_system_integrity": "NONE",
"vulnerable_system_availability": "NONE",
"subsequent_system_confidentiality": null,
"subsequent_system_integrity": null,
"subsequent_system_availability": null,
"exploit_maturity": null,
"confidentiality_requirements": null,
"integrity_requirements": null,
"availability_requirements": null,
"modified_attack_vector": null,
"modified_attack_complexity": null,
"modified_attack_requirements": null,
"modified_privileges_required": null,
"modified_user_interaction": null,
"modified_vulnerable_system_confidentiality": null,
"modified_vulnerable_system_integrity": null,
"modified_vulnerable_system_availability": null,
"modified_subsequent_system_confidentiality": null,
"modified_subsequent_system_integrity": null,
"modified_subsequent_system_availability": null,
"safety": null,
"automatable": null,
"recovery": null,
"value_density": null,
"vulnerability_response_effort": null,
"provider_urgency": null,
"base_score": 7.5,
"base_severity": "HIGH"
}
}
}
}