CVE-2014-0195

OpenSSL DTLS Fragment Buffer Overflow DoS

Title source: metasploit
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2014-0195. PoCs published by ricedu, PezwariNaan, including Metasploit module auxiliary/dos/ssl/dtls_fragment_overflow.

AI-analyzed exploit summary This PoC exploits a heap overflow vulnerability in OpenSSL (CVE-2014-0195) by sending maliciously crafted DTLS handshake fragments to trigger a denial-of-service (DoS) condition. The exploit constructs two oversized handshake fragments and sends them via UDP to the target.

Description

The dtls1_reassemble_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly validate fragment lengths in DTLS ClientHello messages, which allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via a long non-initial fragment.

Exploits (3)

nomisec WORKING POC 3 stars
by ricedu · poc
https://github.com/ricedu/CVE-2014-0195

This PoC exploits a heap overflow vulnerability in OpenSSL (CVE-2014-0195) by sending maliciously crafted DTLS handshake fragments to trigger a denial-of-service (DoS) condition. The exploit constructs two oversized handshake fragments and sends them via UDP to the target.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target: OpenSSL (versions affected by CVE-2014-0195)
No auth needed
Prerequisites: Network access to the target's DTLS port (default: 443/UDP)
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by PezwariNaan · poc
https://github.com/PezwariNaan/CVE-2014-0195

This Python script exploits CVE-2014-0195 by leveraging WordPress's XML-RPC `system.multicall` method to perform brute-force login attempts. It batches multiple login requests into a single HTTP request to bypass rate-limiting and checks for successful authentication.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: WordPress (versions with vulnerable XML-RPC implementation)
No auth needed
Prerequisites: Python 3 · Requests library · Seclists password file
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/dos/ssl/dtls_fragment_overflow.rb

This Metasploit module exploits a buffer overflow in OpenSSL's DTLS implementation (CVE-2014-0195) by sending maliciously crafted fragmented DTLS ClientHello messages, causing a denial of service (DoS). The exploit constructs fragments with mismatched lengths to trigger the overflow.

Classification
Working Poc 100%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target: OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h
No auth needed
Prerequisites: Network access to a vulnerable OpenSSL DTLS service
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (126)

Core 126
Core References
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59669
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59342
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59530
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59990
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1030337
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59454
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59188
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59126
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59306
Third Party Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21678289
Third Party Advisory x_refsource_confirm
http://www.vmware.com/security/advisories/VMSA-2014-0012.html
Issue Tracking, Mailing List, Third Party Advisory vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=142660345230545&w=2
Issue Tracking, Mailing List, Third Party Advisory vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=140266410314613&w=2
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/61254
Issue Tracking, Patch, Third Party Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1103598
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59223
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59895
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/58743
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59449
Third Party Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=isg400001843
Issue Tracking, Mailing List, Third Party Advisory vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=140317760000786&w=2
Third Party Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21677828
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59441
Issue Tracking, Mailing List, Third Party Advisory vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=140621259019789&w=2
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59189
Broken Link vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2014:106
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59300
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-201407-05.xml
Third Party Advisory x_refsource_confirm
http://www.ibm.com/support/docview.wss?uid=swg24037783
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59365
Third Party Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21677695
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59305
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/534161/100/0/threaded
Third Party Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=nas8N1020163
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136473.html
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/58945
Third Party Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=isg400001841
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/58883
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59659
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00011.html
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59429
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59655
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/58660
Third Party Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21676071
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59437
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/67900
Third Party Advisory x_refsource_confirm
http://www.vmware.com/security/advisories/VMSA-2014-0006.html
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59310
Third Party Advisory x_refsource_confirm
http://www.fortiguard.com/advisory/FG-IR-14-018/
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00016.html
Third Party Advisory x_refsource_confirm
http://www.ibm.com/support/docview.wss?uid=swg21676356
Issue Tracking, Mailing List, Third Party Advisory vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=140389274407904&w=2
Third Party Advisory x_refsource_confirm
http://support.citrix.com/article/CTX140876
Issue Tracking, Mailing List, Third Party Advisory vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=140499827729550&w=2
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/58939
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59514
Third Party Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21676419
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/58714
Issue Tracking, Mailing List, Third Party Advisory vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=140482916501310&w=2
Vendor Advisory x_refsource_confirm
http://www.openssl.org/news/secadv_20140605.txt
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/58615
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2014/Dec/23
Third Party Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21676644
Third Party Advisory x_refsource_confirm
http://support.apple.com/kb/HT6443
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59587
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59301
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59784
Broken Link x_refsource_confirm
https://kb.bluecoat.com/index?page=content&id=SA80
Issue Tracking, Mailing List, Third Party Advisory vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=140904544427729&w=2
Third Party Advisory x_refsource_confirm
http://www.f-secure.com/en/web/labs_global/fsc-2014-6
Third Party Advisory x_refsource_confirm
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10629
Third Party Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21678167
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59192
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136470.html
Issue Tracking, Mailing List, Third Party Advisory vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=140752315422991&w=2
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59040
Issue Tracking, Mailing List, Third Party Advisory vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=140389355508263&w=2
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59175
Issue Tracking, Mailing List, Third Party Advisory vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=140448122410568&w=2
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59666
Issue Tracking, Mailing List, Third Party Advisory vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=140431828824371&w=2
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59413
Third Party Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21675821
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59721
Third Party Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21676062
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/58713
Broken Link vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2015:062
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59450
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59287
Third Party Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21683332
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59491
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59364
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59451
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/58977
Third Party Advisory x_refsource_confirm
https://www.novell.com/support/kb/doc.php?id=7015271
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/60571
Third Party Advisory x_refsource_confirm
http://www.blackberry.com/btsc/KB36051
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59528
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/58337
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59518
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59162
Not Applicable third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59490
Issue Tracking, Mailing List, Third Party Advisory vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=140491231331543&w=2

Scores

EPSS 0.9275
EPSS Percentile 99.8%

Details

CWE
CWE-120
Status published
Products (6)
fedoraproject/fedora 19
fedoraproject/fedora 20
mariadb/mariadb 10.0.0 - 10.0.13
openssl/openssl 0.9.8 - 0.9.8za
opensuse/leap 42.1
opensuse/opensuse 13.2
Published Jun 05, 2014
Tracked Since Feb 18, 2026