CVE-2014-0160General(broadcom / application_processing_engine)

CRITICALCVSS 7.5 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch broadcom application_processing_engine systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.

8.8/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-05-25. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-125

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • application_processing_engine
  • application_processing_engine_firmware
  • cp_1543-1
  • cp_1543-1_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 15 mentions across 13 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 7 signals
  • General: 9 classified signals
  • Disclosure: 2 classified signals
  • Peaked 9d ago at 2 mentions (2026-04-21); latest day: 1
  • 15 total mentions across 13 days

Affected systems

Products
application_processing_engineapplication_processing_engine_firmwarecp_1543-1cp_1543-1_firmwaredebian_linuxelan-8.2enterprise_linux_desktopenterprise_linux_serverenterprise_linux_server_ausenterprise_linux_server_eus

35 versions affected across 35 products

Deep dive

Activity timeline15 mentions / 13d
01122Mentions · 2026-02-02: 1Mentions · 2026-03-11: 1Mentions · 2026-04-08: 1Mentions · 2026-04-21: 2Mentions · 2026-04-30: 2Mentions · 2026-05-01: 1Mentions · 2026-06-27: 1Mentions · 2026-06-28: 1Mentions · 2026-07-27: 1Mentions · 2026-08-25: 1Mentions · 2026-08-26: 1Mentions · 2026-09-13: 1Mentions · 2026-09-14: 1PoC Mentioned / Linked · 2026-06-27: 1PoC Mentioned / Linked · 2026-06-28: 1Exploit Tool / Code · 2026-06-27: 1Exploit Tool / Code · 2026-06-28: 1Active Exploitation · 2026-04-08: 1Patch / Workaround · 2026-04-30: 2Technical Details · 2026-02-02: 1Technical Details · 2026-04-08: 1Technical Details · 2026-04-21: 1Technical Details · 2026-04-30: 1Technical Details · 2026-06-27: 1Technical Details · 2026-06-28: 1Technical Details · 2026-08-26: 102-0203-1104-0804-2104-3005-0106-2706-2807-2708-2508-2609-1309-14
Signal classification5 categories
General
960.0%
Disclosure
213.3%
Patch
213.3%
Exploit
16.7%
PoC
16.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-021
General1
2026-03-111
General1
2026-04-081
General1
2026-04-212
Disclosure1General1
2026-04-302
Patch2
2026-05-011
General1
2026-06-271
Exploit1
2026-06-281
PoC1
2026-07-271
General1
2026-08-251
General1
2026-08-261
Disclosure1
2026-09-131
General1
2026-09-141
General1
Full discourse15 posts
  • kalomaze@kalomaze
    General

    just found out about the existence of CVE-2014-0160 (i wasn't old enough to be aware of it back then). wtaf

    Post summary

    The tweet only notes the user’s newfound awareness of CVE-2014-0160 without providing details, context, or evidence of exploitation.

    10002178432.4K
    23.5K followersView on X
  • Nitin Gavhane@NitinGavhane_
    General

    CVE Vulnerabilities That Shaped the Bug Bounty World A quick timeline worth knowing: 1. CVE-2014-0160 • Heartbleed - 2014 2. CVE-2014-6271 • Shellshock - 2014 3. CVE-2016-5195 • Dirty COW - 2016 4. CVE-2017-0144 • EternalBlue - 2017 5. CVE-2017-5638 • Apache Struts RCE - 2017 6. CVE-2018-7600 • Drupalgeddon2 - 2018 7. CVE-2019-0708 • BlueKeep - 2019 8. CVE-2021-44228 • Log4Shell - 2021 9. CVE-2023-34362 • MOVEit - 2023 10. CVE-2024-3094 • XZ Utils - 2024 Learn the CVE → understand the root cause → study the patch → reproduce safely in a lab. #BugBounty #CVE #CyberSecurity #SecurityResearch #EthicalHacking #InfoSec #AppSec #Pentesting

    Post summary

    The post is a simple chronological list of CVE identifiers and years without any discussion of PoC, exploit code, active exploitation, patches, or technical details.

    31411016411.3K
    3.5K followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    PoC

    #CVE-2014-0160 #Heartbleed exploit using #OpenSSL s_client with -tlsextdebug flag to extract up to 64KB of server heap memory per heartbeat request. Tested on #Ubuntu 22.04, #Debian 12, #Kali #Linux. #cybersecurity #develoeprs more detailed info: https://www.valtersit.com/vault/cve20140160-heartbleed-memory-dump-extraction-via-openssl-ffe2d0

    Post summary

    The tweet demonstrates a PoC that uses OpenSSL s_client with -tlsextdebug to leak memory from Heartbleed, with no evidence of active exploitation or patching information.

    040152942
    1.0K followersView on X
  • ぴよ彦@piyohiko_nr
    Disclosure

    Heartbleed(CVE-2014-0160) OpenSSLの脆弱性、Heartbeatの発信時にサーバ上の意図しないメモリ情報を返却してしまう不具合 バッファとして指定されたサイズのメモリ情報をごっそり返してしまう MAXで文学的に捉えるなら「デカい情報ぶつけてお前の心の中曝け出させてやんよ」みたいなイメージ

    Post summary

    The text describes the Heartbleed CVE‑2014‑0160 vulnerability in OpenSSL, explaining how the Heartbeat extension can expose unintended memory data, but it provides no evidence of exploitation or remediation.

    06082730
    862 followersView on X
  • TempleOS stan@1moldetrabalho
    General

    como que pkde essa area ser tao artistica ne meu deus chamaram a cve-2014-0160 de Heartbleed pq a falha de segurança era numa extensão chamada heartbeat kkkkkkkkk

    Post summary

    A casual remark about Heartbleed with no substantive or actionable information provided.

    00040183
    204 followersView on X
  • ねそてち🍆@節制㌠@nesosuke
    General

    OpenSSL Heartbleed Vulnerability CVE-2014-0160 https://www.oracle.com/security-alerts/opensslheartbleedcve-2014-0160.html

    Post summary

    The text references an Oracle security alert for the Heartbleed CVE‑2014‑0160 but provides no additional technical details or actionable information.

    01010268
    924 followersView on X
  • Jon Southurst 🚂 @1259@BitcoinSVtrain
    General

    Like they did with 'Heartbleed Bug' instead of calling it CVE-2014-0160 https://t.co/ZaqoxE5yIb

    Post summary

    The tweet merely references the CVE identifier CVE-2014-0160 and compares it to the nickname 'Heartbleed Bug', offering no additional technical detail, tool, exploit, or patch information.

    10000110
    5.5K followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Exploit

    Exploit Heartbleed (#CVE-2014-0160) with 3OpenSSL s_client: send a malformed heartbeat request with oversized payload length to extract up to 64KB of heap memory. Use -no_ssl3 -no_tls1 for TLS 1.0/1.1, -msg #devops #devsecops #sysadmin #developers More detailed info: https://www.valtersit.com/vault/heartbleed-memory-extraction-via-openssl-sclient-80ed4a/

    Post summary

    The post shares a command-line method using OpenSSL s_client to manually exploit Heartbleed, detailing the vulnerability and linking to further instructions.

    0001050
    966 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-31431 2 - CVE-2026-41940 3 - CVE-2018-17144 4 - CVE-2014-0160 5 - CVE-2010-3962 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post simply lists five trending CVEs without adding any technical or actionable details.

    00010173
    1.7K followersView on X
  • Michael Klapproth@klapproth
    Patch

    @m4xfps @Ha_Sch War das nicht gerade gestern? Wir haben alle auf eine gefixte Version vom haproxy gewartet wegen CVE-2014-0160 in openssl - Heartbleed: https://de.wikipedia.org/wiki/Heartbleed

    Post summary

    The message concerns awaiting a patched Haproxy release to fix the Heartbleed vulnerability (CVE‑2014‑0160).

    1000083
    210 followersView on X
  • Grok@grok
    General

    @wen21447219 @LinearUncle @jesselaunz 你指的是2014年OpenSSL的Heartbleed(心脏出血)漏洞(CVE-2014-0160)。它是TLS heartbeat扩展的实现bug,攻击者只需发个特殊数据包,就能读取服务器内存中最多64KB的敏感数据,包括私钥、密码、聊天记录等。影响了全球大量HTTPS网站,被戏称为“上帝之眼”,因为它像能偷窥服务器“内心”一样。

    Post summary

    The tweet reports on the Heartbleed vulnerability (CVE‑2014‑0160), outlining its technical flaw and widespread impact on HTTPS sites, without mentioning PoC, exploitation tools, patches, or debunking.

    00001544
    8.6M followersView on X
  • Aditya Dheer@dheeraditya1
    General

    CVE & Exploits: Studied the infamous Heartbleed (CVE-2014-0160). A tiny "heartbeat" request that leaked server memory—proof that one small oversight can expose the world.💔 Human Recon: Social Media is the ultimate OSINT goldmine. Your "private" life is often a hacker's roadmap.

    Post summary

    The post briefly references Heartbleed (CVE‑2014‑0160) and its memory leak, but contains no PoC, exploit details, active exploitation evidence, or patch information.

    1000042
    2 followersView on X
  • chaos@konig0000
    General

    CVE Vulnerabilities That Shaped the Bug Bounty World A quick timeline worth knowing: 1. CVE-2014-0160 • Heartbleed - 2014 2. CVE-2014-6271 • Shellshock - 2014 3. CVE-2016-5195 • Dirty COW - 2016 4. CVE-2017-0144 • EternalBlue - 2017 5. CVE-2017-5638 • Apache Struts RCE - 2017 6. CVE-2018-7600 • Drupalgeddon2 - 2018 7. CVE-2019-0708 • BlueKeep - 2019 8. CVE-2021-44228 • Log4Shell - 2021 9. CVE-2023-34362 • MOVEit - 2023 10. CVE-2024-3094 • XZ Utils - 2024 Learn the CVE → understand the root cause → study the patch → reproduce safely in a lab.

    Post summary

    The text provides a historical timeline of major CVEs that shaped the bug bounty world, offering generic advice on studying root causes and patches without detailing specific exploits, PoCs, or active threat intelligence.

    00000121
    19.8K followersView on X
  • Jamaica Cyber Incident Response Team (JaCIRT)@cirtgovjm
    Disclosure

    🚨URGENT ADVISORY🚨CVE-2014-0160, widely known as Heartbleed, is a critical vulnerability in OpenSSL's implementation of the TLS/DTLS heartbeat extension CLICK HERE FOR MORE INFORMATION 👇 https://cirt.gov.jm/advisory/heartbleed-cve-2014-0160-persistently-recurring-openssl-vulnerability-jamaican-networks #JaCIRT #NSOC #CVE #Heartbleed #Vulnerability https://t.co/VdyKyI5sQB

    Post summary

    The tweet highlights the critical Heartbleed vulnerability (CVE‑2014‑0160) and urges readers to check the linked advisory, but it does not provide evidence of active attacks, exploit code, or a patch.

    0000079
    1.2K followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH SEVERITY: CVE-2014-0160 (Heartbleed) CVSS 7.5 - OpenSSL 1[.]0[.]1 < 1[.]0[.]1g vulnerable to memory disclosure via crafted Heartbeat packets. Attackers can extract sensitive data including private keys. Patch immediately to 1[.]0[.]1g+ #CVE #Heartbleed #PatchNow https://t.co/sLcOxJuBvN

    Post summary

    The tweet emphasizes the high severity of Heartbleed (CVE‑2014‑0160) and urges users to apply the 1.0.1g+ patch immediately.

    0000020
    11 followersView on X
CPE platform detail54 entries

54 of 54 entries

PartVendorProductVersionTarget SWTarget HW
Appbroadcomsymantec_messaging_gateway10.6.0--
Appbroadcomsymantec_messaging_gateway10.6.1--
OScanonicalubuntu_linux12.04--
OScanonicalubuntu_linux12.10--
OScanonicalubuntu_linux13.10--
OSdebiandebian_linux6.0--
OSdebiandebian_linux7.0--
OSdebiandebian_linux8.0--
OSfedoraprojectfedora19--
OSfedoraprojectfedora20--
Appfilezilla-projectfilezilla_server---
HWintellianv100---
OSintellianv100_firmware1.20--
OSintellianv100_firmware1.21--
OSintellianv100_firmware1.24--
HWintellianv60---
OSintellianv60_firmware1.15--
OSintellianv60_firmware1.25--
Appmitelmicollab6.0--
Appmitelmicollab7.0--
Appmitelmicollab7.1--
Appmitelmicollab7.2--
Appmitelmicollab7.3--
Appmitelmicollab7.3.0.104--
Appmitelmivoice1.1.2.5lync-
Appmitelmivoice1.1.3.3skype_for_business-
Appmitelmivoice1.2.0.11skype_for_business-
Appmitelmivoice1.3.2.2skype_for_business-
Appmitelmivoice1.4.0.102skype_for_business-
Appopensslopenssl---
OSopensuseopensuse12.3--
OSopensuseopensuse13.1--
OSredhatenterprise_linux_desktop6.0--
OSredhatenterprise_linux_server6.0--
OSredhatenterprise_linux_server_aus6.5--
OSredhatenterprise_linux_server_eus6.5--
OSredhatenterprise_linux_server_tus6.5--
OSredhatenterprise_linux_workstation6.0--
Appredhatgluster_storage2.1--
Appredhatstorage2.1--
Appredhatvirtualization6.0--
HWricons9922l1.0--
OSricons9922l_firmware16.10.3\(3794\)--
HWsiemensapplication_processing_engine---
OSsiemensapplication_processing_engine_firmware2.0--
HWsiemenscp_1543-1---
OSsiemenscp_1543-1_firmware1.1--
Appsiemenselan-8.2---
HWsiemenssimatic_s7-1500---
OSsiemenssimatic_s7-1500_firmware1.5--
HWsiemenssimatic_s7-1500t---
OSsiemenssimatic_s7-1500t_firmware1.5--
Appsiemenswincc_open_architecture3.12--
Appsplunksplunk---

Explore more