'Heartbleed' computer bug threat spreads to firewalls and beyond

Advertisement
By Reuters | Updated: 11 April 2014 09:26 IST

Hackers could crack email systems, security firewalls and possibly mobile phones through the "Heartbleed" computer bug, according to security experts who warned on Thursday that the risks extended beyond just Internet Web servers.

The widespread bug surfaced late on Monday, when it was disclosed that a pernicious flaw in a widely used Web encryption program known as OpenSSL opened hundreds of thousands of websites to data theft. Developers rushed out patches to fix affected web servers when they disclosed the problem, which affected companies from Amazon.com Inc and Google Inc to Yahoo Inc.

Yet pieces of vulnerable OpenSSL code can be found inside plenty of other places, including email servers, ordinary PCs, phones and even security products such as firewalls. Developers of those products are scrambling to figure out whether they are vulnerable and patch them to keep their users safe.

Advertisement

"I am waiting for a patch," said Jeff Moss, a security adviser to the U.S. Department of Homeland Security and founder of the Def Con hacking conference. Def Con's network uses an enterprise firewall from McAfee, which is owned by Intel Corp's security division.

Advertisement

He said he was frustrated because people had figured out that his email and Web traffic is vulnerable and posted about it on the Internet - but he can't take steps to remedy the problem until Intel releases a patch.

"Everybody is going through the exact same thing I'm going through, if you are going through a vendor fix," he said.

Advertisement

An Intel spokesman declined comment, referring Reuters to a company blog that said: "We understand this is a difficult time for businesses as they scramble to update multiple products from multiple vendors in the coming weeks. The McAfee products that use affected versions of OpenSSL are vulnerable and need to be updated."

It did not say when they would be released.

The Heartbleed vulnerability went undetected for about two years and can be exploited without leaving a trace, so experts and consumers fear attackers may have compromised large numbers of networks without their knowledge.

Advertisement

Companies and government agencies are now rushing to understand which products are vulnerable, then set priorities for fixing them. They are anxious because researchers have observed sophisticated hacking groups conducting scans of the Internet this week in search of vulnerable servers.

"Every security person is talking about this," said Chris Morales, practice manager with the cybersecurity services firm NSS Labs.

Cisco Systems Inc, the world's biggest telecommunications equipment provider, said on its website that it is reviewing dozens of products to see if they are safe. It uncovered about a dozen that are vulnerable, including a TelePresence video conferencing server, a version of the IOS software for managing routers. A company spokesman declined to comment on how those issues might affect users, saying Cisco would provide more information as it became available.

Oracle Corp has not posted such an advisory on its support site. Company spokeswoman Deborah Hellinger declined to comment on Heartbleed.

Microsoft Corp, which runs a cloud computing and storage service, the Xbox platform and has hundreds of millions of Windows and Officer users, said in a statement that "a few services continue to be reviewed and updated with further protections." It did not identify them.

Officials with technology giants IBM and Hewlett-Packard Co could not be reached. EMC Corp and Dell said they had no immediate comment.

Security experts said the vulnerable code is also found in some widely used email server software, the online browser anonymizing tool Tor and OpenVPN, as well as some online games and software that runs Internet-connected devices such as webcams and mobile phones.

Jeff Forristal, chief technology officer of Bluebox Security, said that version 4.1.1 of Google's Android operating system, known as Jelly Bean, is also vulnerable. Google officials declined comment on his finding.

Other security experts said that they would avoid using any device with the vulnerable software in it, but that it would take a lot of effort for a hacker to extract useful data from a vulnerable Android phone.

© Thomson Reuters 2014

 

Catch the latest from the Consumer Electronics Show on Gadgets 360, at our CES 2026 hub.

Advertisement

Related Stories

Popular Mobile Brands
  1. Flipkart Reveals Deals on Phones For its Upcoming Sale: See Offers
  2. Here's How Much the Motorola Signature Could Cost in India
  3. Here Are the Top 10 Deals on Smartphones During the Upcoming Amazon Sale
  4. Amazon Great Republic Day Sale 2026: Here Are the Top Deals on Laptops
  5. Redmi Note 15 Pro 5G India Variant Spied on Geekbench, Could Launch Soon
  6. Nothing Phones Will Get More Expensive in 2026
  7. Not China, But This New Country Will Make the New Google Pixel 11 Series
  8. Google Pixel 10a Launch Timeline, Colourways and Storage Options Leaked
  1. Redmi Note 15 Pro 5G India Launch Seems Imminent After Smartphone Appears on Geekbench
  2. Battlefield 6 Season 2 Delayed to February as EA Extends Season 1
  3. CERT-In Urges Android Users to Update Smartphones After Google Patches Critical Dolby Vulnerability
  4. Apple Led Market as Global Smartphone Shipments Rose 2.3 Percent YoY in Q4 2025 Despite Growing Memory Shortage: IDC
  5. Red Magic 11 Air Design, Colour Options and Display Features Confirmed
  6. Motorola Signature Box Price in India, Launch Date Leaked Ahead of Arrival: Expected Specifications
  7. Dhandoraa Now Streaming on Prime Video: Know Everything About This Telugu Drama Film Online
  8. Oppo 6t Series, Oppo A6 4G, Oppo A6x 4G Specifications, Colourways Listed Online; Could Launch Soon
  9. Samsung Galaxy S26 Leak: Base Model Could Finally Get 45W Fast Charging Upgrade
  10. Haier H5E Series 4K Smart Google TVs With Bezel-Less Design Launched in India: Price, Features
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.