Definition · TLS & Certificates
What is POODLE Attack?
POODLE — Padding Oracle On Downgraded Legacy Encryption, CVE-2014-3566 — was disclosed in October 2014. It exploited a design flaw in SSL 3.0: when using a CBC-mode cipher suite, the padding bytes appended to each record were not covered by the message authentication code. An attacker who could modify records and observe whether the server accepted or rejected them therefore had a padding oracle, and could recover one byte of plaintext at a time from a chosen position — enough, with sufficient requests, to extract a session cookie and hijack an authenticated session.
Why downgrade mattered
By 2014 virtually every browser and server supported TLS 1.0 or better, so SSL 3.0 was rarely negotiated by choice. The attack depended on the “downgrade dance”: clients that failed to complete a handshake would retry with an older protocol version, ostensibly for compatibility with broken servers. An on-path attacker could deliberately break the first handshakes until the client fell back to SSL 3.0, then run the padding oracle. The fix for that behaviour was the TLS_FALLBACK_SCSV signalling mechanism, defined in RFC 7507, which lets a client mark a retry as a fallback so a server that supports better can refuse it.
A related issue, CVE-2014-8730, affected some TLS implementations that did not verify CBC padding strictly, making them vulnerable to the same technique over TLS rather than SSL 3.0 — a bug in specific products, not a flaw in TLS.
Its status today
POODLE is largely historical. SSL 3.0 was formally deprecated by RFC 7568, removed from browsers, and disabled by default across mainstream server software; TLS 1.0 and 1.1 have since been deprecated too. The modern equivalent of the POODLE remediation is simply to offer TLS 1.2 and TLS 1.3 only, and to prefer AEAD cipher suites such as AES-GCM and ChaCha20-Poly1305 over CBC constructions altogether.
External scanners still report SSL 3.0 support where they find it. In practice this now indicates a legacy appliance, load balancer or embedded device that has never had its configuration revisited — the same population of hosts that tends to turn up self-signed certificates and unpatched software. Treat it as a security misconfiguration finding about maintenance, rather than as evidence of imminent exploitation.
Related concepts
See TLS, TLS handshake, perfect forward secrecy, HSTS and Heartbleed.