CVE-2022-22576 is an improper authentication vulnerability in curl versions 7.33.0 through 7.82.0, allowing OAUTH2-authenticated connections to be reused without proper credential verification for SASL-enabled protocols like SMTP, IMAP, POP3, and LDAP. This vulnerability affects products from vendors such as Brocade, Debian, Haxx, NetApp, and Splunk. With a CVSS score of 8.1 (HIGH), it presents a significant risk, allowing an attacker with low privileges to achieve high confidentiality and integrity impacts over the network with low attack complexity. While there is no evidence of active exploitation, public exploit code, or Metasploit/Nuclei modules, there has been limited community discussion and media coverage, including a Siemens advisory.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.33.0, < 7.83.0CPE matchmatch criteria | cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:clustered_data_ontap:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:solidfire_\&_hci_management_node:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
August Third Party Package Updates in Splunk Universal Forwarder
Aug 30, 2023CVE-2022-22576
Jun 14, 2022An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects SASL-enabled protocols: SMPTP(S) IMAP(S) POP3(S) and LDAP(S) (openldap only).
May 10, 2022curl: OAUTH2 bearer bypass in connection re-use
Apr 27, 2022OAUTH2 bearer bypass in connection reuse
Apr 27, 2022