CVE-2022-2068 is a command injection vulnerability in the c_rehash script, affecting OpenSSL versions 3.0.0-3.0.3, 1.1.1-1.1.1o, and 1.0.2-1.0.2ze, as well as products from Broadcom, Debian, Fedora Project, NetApp, and Siemens. This vulnerability stems from inadequate sanitization of shell metacharacters in certificate filenames, allowing an attacker to execute arbitrary commands with the script's privileges, particularly on systems where c_rehash is automatically executed. The vulnerability has a CVSS score of 7.3 (HIGH), indicating a local attack vector with low complexity, requiring user interaction, and potentially leading to high impacts on confidentiality, integrity, and availability. Its FAUCET Risk Score is 95/100, and it is categorized under CWE-78 (Improper Neutralization of Special Elements used in an OS Command). Currently, there is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. While there are only two community mentions and one media article, the EPSS score suggests a higher-than-average potential for exploitation compared to other CVEs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.0.2, < 1.0.2zfCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* | ||
>= 1.1.1, < 1.1.1pCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* | ||
>= 3.0.0, < 3.0.4CPE matchmatch criteria | cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP Universal Print Driver Series (PCL 6 and PostScript) - Potential Security Vulnerabilities
Jan 29, 2025AS-2022-009: OpenSSL
Aug 29, 2022August Third Party Package updates in Splunk Enterprise and Universal Forwarders
Aug 16, 2022openssl: the c_rehash script allows command injection
Jun 21, 2022The c_rehash script allows command injection
Jun 14, 2022OpenSSL Vulnerabilities
OpenSSL Vulnerabilities Fixed
OpenSSL Vulnerabilities
OpenSSL Vulnerabilities
OpenSSL Vulnerabilities