CVE•Published 2014-10-15•Modified 2026-05-28•1 article on news•7 live references•NVD data
CVE-2014-3566Redhat · Enterprise_linux
Vulnerability data via NVD (ingested)
CVSS v3.1
3.4
LOW
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N
EPSS percentile
100
Exploit Prediction Scoring System · top 0% of all CVEs
Weaknesses (CWE)
Description
The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.
Timeline
Published 2014-10-15
Modified 2026-05-28
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
Shodan · vuln tag117,506 hosts
vuln:CVE-2014-3566Hosts Shodan has explicitly fingerprinted as vulnerable.
Shodan · OS
os:"Enterprise Linux"Hosts Shodan identified as running Enterprise Linux.
More intel sources (5)
Shodan report
vuln:CVE-2014-3566Country / ASN / product breakdown for the vuln query.
Censys
vulnerabilities.cve_id: CVE-2014-3566Censys host search filtered to this CVE id.
grep.app
CVE-2014-3566Public source-code mentions — fast PoC discovery.
GitHub code
CVE-2014-3566GitHub code search for direct mentions.
Google dork
"CVE-2014-3566" exploit -site:nvd.nist.govWrite-ups and news, NVD excluded.
Known PoCs on GitHub (4)
CVE-2014-35664 repos
Ostorlab/KEVunknown
Ostorlab KEV: One-command to detect most remotely known exploitable vulnerabilities. Sourced from CISA KEV, Google's Tsunami, Ostorlab's Asteroid and Bug Bounty programs.
ggrandes/bouncerJava
Bouncer is a network TCP port redirector/forward proxy (like rinetd) with extra features like Reverse tunneling (like ssh -R), SSL tunneling (like stunnel), connection Failover, Lo…
Scottcjn/macosx-security-patchesC
Security patches for legacy Mac OS X (Panther, Tiger, Leopard, Snow Leopard)
Untouchable17/HTTP-ExploitKitPython
Repository contains a collection of scripts designed to demonstrate and exploit various vulnerabilities in HTTP and related protocols