McAfee Firewall Enterprise OpenSSL Information Disclosure (SB10071) (Heartbleed)

High Nessus Plugin ID 73834


The remote host is affected by an information disclosure vulnerability.


The remote host has a version of McAfee Firewall Enterprise installed that is affected by an out-of-bounds read error, known as Heartbleed, in the TLS/DTLS implementation due to improper handling of TLS heartbeat extension packets. A remote attacker, using crafted packets, can trigger a buffer over-read, resulting in the disclosure of up to 64KB of process memory, which contains sensitive information such as primary key material, secondary key material, and other protected content.


Apply 8.3.2 ePatch 14 per the vendor advisory.

See Also

Plugin Details

Severity: High

ID: 73834

File Name: mcafee_firewall_enterprise_SB10071.nasl

Version: $Revision: 1.9 $

Type: local

Family: Firewalls

Published: 2014/05/02

Modified: 2017/02/21

Dependencies: 73830

Risk Information

Risk Factor: High


Base Score: 9.4

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:N

Temporal Vector: CVSS2#E:POC/RL:OF/RC:C

Vulnerability Information

CPE: x-cpe:/a:mcafee:firewall_enterprise

Required KB Items: Host/McAfeeFE/version, Host/McAfeeFE/version_display, Host/McAfeeFE/installed_patches

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2014/04/10

Vulnerability Publication Date: 2014/02/24

Exploitable With

Core Impact

Reference Information

CVE: CVE-2014-0160

BID: 66690

OSVDB: 105465

CERT: 720951

EDB-ID: 32745, 32764, 32791, 32998