Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-0778

65
FAUCET Score

CVE-2022-0778 is a denial-of-service vulnerability in OpenSSL versions 1.0.2, 1.1.1, and 3.0, affecting the BN_mod_sqrt() function. This bug causes an infinite loop when parsing specially crafted certificates or private keys containing invalid elliptic curve parameters, impacting products like Debian, Fedora, MariaDB, and Node.js. With a CVSS score of 7.5 (High), it can be exploited remotely with low attack complexity, leading to a complete denial of service. While there is no known active exploitation or public exploit code, the vulnerability has garnered significant community attention and media coverage, indicating its potential impact.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.0.2, < 1.0.2zdCPE matchmatch criteria
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
>= 1.1.0, < 1.1.1nCPE matchmatch criteria
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
>= 3.0.0, < 3.0.2CPE matchmatch criteria
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
9.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
10.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
70.56%
Probability of exploitation in next 30 days
EPSS Percentile
99.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
This CVE's current EPSS score of 0.7056 is in the 99th percentile among its peer group of 51,455 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (86)

check_pointpatch availablevia llm_extracted
Fixed in: OpenSSL 1.1.1n
View patch
elementpatch availablevia llm_extracted
Fixed in: 1.1.1n (for OpenSSL)
View patch
fuji_electricpatch availablevia llm_extracted
View patch
githubpatch availablevia llm_extracted
View patch
intermeshpatch availablevia llm_extracted
Fixed in: 1.1.1n (for OpenSSL)
View patch
latchsetpatch availablevia llm_extracted
View patch
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 ARMFixed in: 1.1.1k-9
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 1.1.1k-12
microsoftpatch availablevia msrc
Product: azl3 edk2 20240223gitedc6681206c1-1 on Azure Linux 3.0Fixed in: 20240223gitedc6681206c1-1
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 1.1.1k-12
microsoftpatch availablevia msrc
Product: azl3 edk2 20230301gitf80f052277c8-37 on Azure Linux 3.0Fixed in: 20240223gitedc6681206c1-2
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 ARMFixed in: 20240223gitedc6681206c1-2
microsoftpatch availablevia msrc
Product: cbl2 openssl 1.1.1k-12 on CBL Mariner 2.0Fixed in: 1.1.1k-12
microsoftpatch availablevia msrc
Product: cm1 openssl 1.1.1k-9 on CBL Mariner 1.0Fixed in: -
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 x64Fixed in: 20240223gitedc6681206c1-2
microsoftpatch availablevia msrc
Product: 18763-16820Fixed in: -
microsoftpatch availablevia msrc
Product: 18764-16823Fixed in: 1.1.1k-12
microsoftpatch availablevia msrc
Product: 18131-17084Fixed in: 20240223gitedc6681206c1-1
microsoftpatch availablevia msrc
Product: 17859-17084Fixed in: 20240223gitedc6681206c1-2
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 x64Fixed in: 1.1.1k-9
opensslpatch availablevia llm_extracted
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-openssl-1:1.1.1g-11.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-openssl-chil-0:1.0.0-11.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-openssl-pkcs11-0:0.4.10-26.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6 Extended Lifecycle SupportFixed in: openssl-0:1.0.1e-60.el6_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: openssl-1:1.0.2k-25.el7_9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.3 Advanced Update SupportFixed in: openssl-1:1.0.1e-62.el7_3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.4 Advanced Update SupportFixed in: openssl-1:1.0.2k-10.el7_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.6 Advanced Update Support(Disable again in 2026 - SPRHEL-7118)Fixed in: openssl-1:1.0.2k-18.el7_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.6 Telco Extended Update SupportFixed in: openssl-1:1.0.2k-18.el7_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.6 Update Services for SAP SolutionsFixed in: openssl-1:1.0.2k-18.el7_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.7 Advanced Update SupportFixed in: openssl-1:1.0.2k-21.el7_7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.7 Telco Extended Update SupportFixed in: openssl-1:1.0.2k-21.el7_7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.7 Update Services for SAP SolutionsFixed in: openssl-1:1.0.2k-21.el7_7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: compat-openssl10-1:1.0.2o-4.el8_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: openssl-1:1.1.1k-6.el8_5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.1 Update Services for SAP SolutionsFixed in: openssl-1:1.1.1c-5.el8_1.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Extended Update SupportFixed in: openssl-1:1.1.1c-19.el8_2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Extended Update SupportFixed in: openssl-1:1.1.1g-16.el8_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: compat-openssl11-1:1.1.1k-4.el9_0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5Fixed in: openssl
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5.6 on RHEL 7Fixed in: jws5-tomcat-0:9.0.50-5.redhat_00007.1.el7jws
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5.6 on RHEL 7Fixed in: jws5-tomcat-native-0:1.2.30-4.redhat_4.el7jws
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5.6 on RHEL 8Fixed in: jws5-tomcat-0:9.0.50-5.redhat_00007.1.el8jws
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5.6 on RHEL 8Fixed in: jws5-tomcat-native-0:1.2.30-4.redhat_4.el8jws
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Virtualization 4 for Red Hat Enterprise Linux 7Fixed in: redhat-virtualization-host-0:4.3.22-20220330.1.el7_9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Virtualization 4 for Red Hat Enterprise Linux 8Fixed in: redhat-virtualization-host-0:4.5.0-202205291010_8.6
View patch
redhatpatch availablevia redhat_api
Product: Text-Only JBCSFixed in: openssl
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services for RHEL 8Fixed in: jbcs-httpd24-nghttp2-0:1.39.2-41.el8jbcs
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services for RHEL 8Fixed in: jbcs-httpd24-apr-util-0:1.6.1-91.el8jbcs
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services for RHEL 8Fixed in: jbcs-httpd24-curl-0:7.78.0-3.el8jbcs
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services for RHEL 8Fixed in: jbcs-httpd24-httpd-0:2.4.37-80.el8jbcs
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services for RHEL 8Fixed in: jbcs-httpd24-mod_cluster-native-0:1.3.16-10.Final_redhat_2.el8jbcs
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services for RHEL 8Fixed in: jbcs-httpd24-mod_http2-0:1.15.7-22.el8jbcs
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services for RHEL 8Fixed in: jbcs-httpd24-mod_jk-0:1.2.48-29.redhat_1.el8jbcs
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services for RHEL 8Fixed in: jbcs-httpd24-mod_md-1:2.0.8-41.el8jbcs
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services for RHEL 8Fixed in: jbcs-httpd24-mod_security-0:2.9.2-68.GA.el8jbcs
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services for RHEL 8Fixed in: jbcs-httpd24-openssl-1:1.1.1g-11.el8jbcs
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services for RHEL 8Fixed in: jbcs-httpd24-openssl-chil-0:1.0.0-11.el8jbcs
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services for RHEL 8Fixed in: jbcs-httpd24-openssl-pkcs11-0:0.4.10-26.el8jbcs
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-apr-util-0:1.6.1-91.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-curl-0:7.78.0-3.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-httpd-0:2.4.37-80.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-mod_cluster-native-0:1.3.16-10.Final_redhat_2.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-mod_http2-0:1.15.7-22.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-mod_jk-0:1.2.48-29.redhat_1.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-mod_md-1:2.0.8-41.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-mod_security-0:2.9.2-68.GA.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-nghttp2-0:1.39.2-41.jbcs.el7
View patch
rustpatch availablevia ghsa
Product: openssl-srcFixed in: 111.18.0
rustpatch availablevia ghsa
Product: openssl-srcFixed in: 300.0.5
capnprotovendor investigatingvia llm_extracted
View patch
cephvendor investigatingvia llm_extracted
ciscovendor investigatingvia llm_extracted
View patch
d-linkvendor investigatingvia llm_extracted
hedgedocvendor investigatingvia llm_extracted
View patch
hpvendor investigatingvia llm_extracted
View patch
humansignalvendor investigatingvia llm_extracted
hyperledgervendor investigatingvia llm_extracted
jenkinsvendor investigatingvia llm_extracted
View patch
lycheeorgvendor investigatingvia llm_extracted
View patch
m2teamvendor investigatingvia llm_extracted
roundcubevendor investigatingvia llm_extracted
yokogawavendor investigatingvia llm_extracted
View patch
redhatno patchvia redhat_api
Product: Red Hat Advanced Cluster Management for Kubernetes 2Fixed in: rhacm2/management-ingress-rhel8
redhatend of lifevia redhat_api
Product: Red Hat JBoss Web Server 3Fixed in: openssl

Vendor Advisories (30)

microsoft2024-Sep/CVE-2022-0778

CVE-2022-0778

Sep 10, 2024
hpllm-hp-55957b7719c53e63

OpenSSL vulnerability (CVE-2022-0778)

Apr 27, 2022
ciscollm-cisco-c472c3325b2f16ec

OpenSSL vulnerability (CVE-2022-0778)

Apr 27, 2022
roundcubellm-roundcube-ba643b3a22576d13HIGH

Vulnerability in routers FL MGUARD and TC MGUARD

Apr 27, 2022
cephllm-ceph-dd80cd7bf092545bHIGH

Vulnerability in routers FL MGUARD and TC MGUARD

Apr 27, 2022
humansignalllm-humansignal-c197c4b1b03df537HIGH

Vulnerability in routers FL MGUARD and TC MGUARD

Apr 27, 2022
d-linkllm-d-link-4a10f311f6b15d47HIGH

Vulnerability in routers FL MGUARD and TC MGUARD

Apr 27, 2022
capnprotollm-capnproto-d68bcac2e31c1484

OpenSSL vulnerability (CVE-2022-0778)

Apr 27, 2022
hedgedocllm-hedgedoc-e7a8bcfb283f4bac

OpenSSL vulnerability (CVE-2022-0778)

Apr 27, 2022
jenkinsllm-jenkins-5cc08c547c89b003

OpenSSL vulnerability (CVE-2022-0778)

Apr 27, 2022
m2teamllm-m2team-cb63b7c9d0999c9eHIGH

Vulnerability in routers FL MGUARD and TC MGUARD

Apr 27, 2022
yokogawallm-yokogawa-de285703122b8b52

OpenSSL vulnerability (CVE-2022-0778)

Apr 27, 2022
lycheeorgllm-lycheeorg-4383e885b90641f7

OpenSSL vulnerability (CVE-2022-0778)

Apr 27, 2022
hyperledgerllm-hyperledger-8d3de5f91f772eefHIGH

Vulnerability in routers FL MGUARD and TC MGUARD

Apr 27, 2022
m2teamllm-m2team-41bf9cb22f24a510CRITICAL

Multiple ctrlX CORE vulnerabilities

Apr 20, 2022
d-linkllm-d-link-1b06970e59fff350CRITICAL

Multiple ctrlX CORE vulnerabilities

Apr 20, 2022
roundcubellm-roundcube-8900788926ebda25CRITICAL

Multiple ctrlX CORE vulnerabilities

Apr 20, 2022
cephllm-ceph-757e29f49fd4489eCRITICAL

Multiple ctrlX CORE vulnerabilities

Apr 20, 2022
hyperledgerllm-hyperledger-3131efc9fc3bed9eCRITICAL

Multiple ctrlX CORE vulnerabilities

Apr 20, 2022
humansignalllm-humansignal-a731b4173ec8e579CRITICAL

Multiple ctrlX CORE vulnerabilities

Apr 20, 2022
githubllm-github-bfb2a982c4147292MEDIUM

AS-2022-004: OpenSSL

Mar 29, 2022
latchsetllm-latchset-4c09c4aaa6d2c7dbMEDIUM

Updates for OpenSSL vulnerabilities

Mar 22, 2022
rustGHSA-x3mh-jvjw-3xwxhigh

openssl-src's infinite loop in `BN_mod_sqrt()` reachable when parsing certificates

Mar 16, 2022
redhatCVE-2022-0778Important

openssl: Infinite loop in BN_mod_sqrt() reachable when parsing certificates

Mar 15, 2022
microsoft2022-Mar/CVE-2022-0778Important

Infinite loop in BN_mod_sqrt() reachable when parsing certificates

Mar 8, 2022
fuji_electricllm-fuji_electric-baa8ffbe75234471HIGH

OpenSSL Vulnerability CVE-2022-0778 Resolution

intermeshllm-intermesh-3dfed4c215a51ee9HIGH

OpenSSL update to resolve CVE-2022-0778

opensslllm-openssl-0d39dd92104417e2

OpenSSL update to resolve CVE-2022-0778

check_pointllm-check_point-0ef76d153a926c16

OpenSSL update to resolve CVE-2022-0778

elementllm-element-f3cfe37e2324968aHIGH

OpenSSL update to resolve CVE-2022-0778

References

cert-portal.siemens.com / productcert/html/ssa-019200.html
cert-portal.siemens.com / productcert/html/ssa-028723.html
cert-portal.siemens.com / productcert/html/ssa-108696.html
cert-portal.siemens.com / productcert/html/ssa-398330.html
cert-portal.siemens.com / productcert/html/ssa-712929.html
packetstormsecurity.com / files/167344/OpenSSL-1.0.2-1.1.1-3.0-BN_mod_sqrt-Infinite-Loop.html
Third Party AdvisoryVDB Entry
cert-portal.siemens.com / productcert/pdf/ssa-712929.pdf
Third Party Advisory
seclists.org / fulldisclosure/2022/May/33
Mailing ListThird Party Advisory
seclists.org / fulldisclosure/2022/May/35
Mailing ListThird Party Advisory
seclists.org / fulldisclosure/2022/May/38
Mailing ListThird Party Advisory
git.openssl.org / gitweb
git.openssl.org / gitweb
git.openssl.org / gitweb
lists.debian.org / debian-lts-announce/2022/03/msg00023.html
Mailing ListThird Party Advisory
lists.debian.org / debian-lts-announce/2022/03/msg00024.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/323SNN6ZX7PRJJWP2BUAFLPUAE42XWLZ
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/GDB3GQVJPXJE7X5C5JN6JAA4XUDWD6E6
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/W6K3PR542DXWLEFFMFIDMME4CWMHJRMG
psirt.global.sonicwall.com / vuln-detail/SNWLID-2022-0002
Third Party Advisory
security.gentoo.org / glsa/202210-02
Third Party Advisory
security.netapp.com / advisory/ntap-20220321-0002
Third Party Advisory
security.netapp.com / advisory/ntap-20220429-0005
Third Party Advisory
security.netapp.com / advisory/ntap-20240621-0006
support.apple.com / kb/HT213255
Third Party Advisory
support.apple.com / kb/HT213256
Third Party Advisory
support.apple.com / kb/HT213257
Third Party Advisory
debian.org / security/2022/dsa-5103
Third Party Advisory
openssl.org / news/secadv/20220315.txt
Vendor Advisory
oracle.com / security-alerts/cpuapr2022.html
Third Party Advisory
oracle.com / security-alerts/cpujul2022.html
Third Party Advisory
tenable.com / security/tns-2022-06
Third Party Advisory
tenable.com / security/tns-2022-07
Third Party Advisory
tenable.com / security/tns-2022-08
Third Party Advisory
tenable.com / security/tns-2022-09
Third Party Advisory