CVE-2014-3566
MEDIUM 4.3EPSS 100.0%
The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.
- CVSS v3.1
- 3.4 LOW
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N - CVSS v3.1
- 3.4 LOW
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N - CVSS v2.0
- 4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N - EPSS
- 100.00% chance of exploitation in the next 30 days, 100th percentile
- Published
- 2014-10-15
- Updated
- 2026-05-28
Proof-of-concept exploits (9)
- mpgn/poodle-PoC265★ · 2023-10-06
- FroggDev/BASH_froggPoodler0★ · 2015-02-16
- SECURED-FP7/secured-psa-reencrypt0★ · 2016-11-11
- YongJian-YJ/TLS-Poodle-Attack0★ · 2024-12-09
- ldw129/SC4010-POODLE-Attack-PoC1★ · 2024-12-09
- mikesplain/CVE-2014-3566-poodle-cookbook2★ · 2014-10-16
- r3p3r/1N3-MassBleed0★ · 2018-01-01
- uthrasri/openssl_g2.5_CVE-2014-35660★ · 2023-11-07
- josecl200/VC-PoodlePOC