ZeroHour
Security Affairspublished ()ingested @securityaffairs

Roughly 200,000 Devices still affected by the Heartbleed vulnerability

mediumVulnerabilityimportance 35CVE-2014-0160

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2014-0160
Heartbleed: unauthenticated memory disclosure in OpenSSL TLS/DTLS heartbeat handling

The flaw (CVE-2014-0160, widely known as 'Heartbleed') is an out-of-bounds read (CWE-125) in the TLS and DTLS implementations of OpenSSL, caused by improper handling of Heartbeat Extension packets. A remote, unauthenticated attacker triggers it by sending a crafted heartbeat request whose declared payload length exceeds the data actually sent, causing OpenSSL to copy up to roughly 64 KB of adjacent process memory into the response. The attacker gains chunks of process memory per request — potentially TLS private keys, session cookies, usernames and passwords — and can repeat the request to harvest more, typically without any trace in logs. Any server or client running a vulnerable OpenSSL release that enables TLS or DTLS heartbeats is affected, which at the time of disclosure included hundreds of thousands of internet-exposed HTTPS servers as well as appliances, load balancers, and bundled libraries. Exploitation is confirmed in the wild: the vulnerability is listed in CISA KEV (added 2022-05-04, required action: apply updates per vendor instructions) and EPSS assigns it the maximum 100% probability of exploitation within 30 days.

Do: Apply OpenSSL updates per your OS or vendor's instructions — the upstream fix at the time of the 2014 disclosure was OpenSSL 1.0.1g, with most distributions shipping backported patches — and restart or rebuild every service linked against OpenSSL, including bundled copies in load balancers, appliances, and VPN or management interfaces. Because leaked memory can include TLS private keys, treat keys and certificates on affected endpoints as compromised: rotate keys, reissue and revoke certificates, and invalidate session cookies and credentials that may have leaked. Confirm the heartbeat fix is present on all TLS/DTLS endpoints to satisfy the CISA KEV required action.

100% KEV
  • OpenSSL
mass≈500,000+ internet-exposed HTTPS servers at the time of disclosure, plus vastly larger embedded/library deployments
Full article251 words · extracted from securityaffairs.com · click to collapse

More than two years after the disclosure of the HeartBleed bug, 200,000 services are still affected.

Systems susceptible to Heartbleed attacks are still too many, despite the flaw was discovered in 2014 nearly 200,000 systems are still affected.

Shodan made a similar search in November 2015 when he found 238,000 results, the number dropped to 237,539 results in March 2016.

The Heartbleed Bug, tracked as CVE-2014-0160, is a serious flaw in the popular OpenSSL library that allows an attacker to reveal up to 64kB of memory to a connected client or server.

Nearly 3 years later and we’re still looking at ~200,000 services vulnerable to Heartbleed: https://t.co/KU04PtWTJU pic.twitter.com/6mZhCUCVu6

— John Matherly (@achillean) 22 gennaio 2017

Now the Shodan CEO John Matherly revealed that more than two years after its disclosure, about 200,000 services remain affected by the Heartbleed flaw due to the usage of unpatched OpenSSL instances.

Most of the vulnerable installations are located in the United States (42,032), followed by Korea (15,380), China (14,116), and  Germany (14,072).

Heartbleed vulnerability devices

According to Matherly, the list of top affected organizations includes IT giants like Amazon, Verizon Wireless, German ISP Strato, OVH, 1&1 Internet, and Comcast.

The most affected product is Apache HTTP Server (httpd), in particular versions 2.2.22 and 2.2.15. Top operating system is Linux 3.x, followed by Linux 2.6.x and Windows 7/8. According to the report published by Shodan, more than 70,000 devices run services with expired SSL certificates.

[adrotate banner=”9″]

Pierluigi Paganini

(Security Affairs –  OpenSSL, Heartbleed)

[adrotate banner=”12″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/55594/hacking/heartbleed-vulnerability-devices.html