lowREV. 01

CVE-2014-3566POODLE — Padding Oracle in SSL 3.0

The third version of the secure sockets protocol pads blocks in a way a network attacker can probe one byte at a time, recovering a session cookie from traffic they can see and influence.

YOUR NEXT MOVE

Retire the third version of the secure sockets protocol on both ends of every connection, and require its transport-layer successor.

Read the risk

THE VITAL STATS
CVSS score
3.4/ 10
CVSS v3.1
EPSS probability
100%
Likelihood of exploitation
Attack complexity
High
Conditions needed to exploit
Known exploited
Not listed
CVE published
2014-10-15
Exploit published
Not recorded
Confidence
medium
Kill chain
credential access
MITRE ATT&CK
T1040
Severity
low

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N

Attacker needsA position on the network path and the ability to trigger repeated requests

Behind the card

5 REFERENCES
Field-level provenanceTRACE THE SOURCES +

Which source supports each field, when it was retrieved, and who extracted it.

FieldsSourceRetrievedExtractorConfidence
cvss, exploitation.attack_complexity, exploitation.exploit_available, references, published_atnvd.nist.gov2026-08-07scrty-crds-pipeline/0.1high
epssapi.first.org2026-08-07scrty-crds-pipeline/0.1high
title, summary, severity, remediation, mitre_attack, kill_chain, recommended_action, confidence, tags, exploitation.prerequisitesnvd.nist.gov2026-08-07claude-codehigh

Printing history

THE RECORD
  1. r1Initial base card

First printing. This card has not been reprinted since publication.

crds:cve-2014-3566 · CRDS 0.1 · Issued 2026-08-07