CVE-2022-3786 is a buffer overrun vulnerability in OpenSSL versions 3.0 and later, affecting products like Fedora and Node.js that utilize these OpenSSL versions. This flaw occurs during X.509 certificate verification, specifically in name constraint checking, where a malicious email address in a certificate can cause a denial of service by overflowing the stack with '.' characters. The vulnerability has a CVSS score of 7.5 (High) due to its network-based attack vector and low complexity, potentially impacting both TLS clients and servers. While not currently listed in CISA's KEV catalog or having public exploit code, its high EPSS score and significant community discussion (11 mentions) indicate a notable level of concern and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.0.0, < 3.0.7CPE match | cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* | ||
36CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:* | ||
37CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* | ||
>= 18.0.0, < 18.11.0CPE matchmatch criteria | cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:* | ||
18.12.0CPE matchmatch criteria | cpe:2.3:a:nodejs:node.js:18.12.0:*:*:*:lts:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2022-3602, CVE-2022-3786: OpenSSL Vulnerabilities
Nov 14, 2022CVE-2022-3602, CVE-2022-3786: OpenSSL Vulnerabilities
Nov 14, 2022OpenSSL: CVE-2022-3786 X.509 certificate verification buffer overrun
Nov 8, 2022X.509 Email Address Variable Length Buffer Overflow
Nov 1, 2022Okta Access Gateway Advisory for CVE-2022-3602 and CVE-2022-3786
Nov 1, 2022OpenSSL 3 Vulnerabilities Affecting OpenVPN Products
Nov 1, 2022OpenSSL: X.509 Email Address Variable Length Buffer Overflow
Nov 1, 2022Splunk’s response to OpenSSL’s CVE-2022-3602 and CVE-2022-3786
Nov 1, 2022Okta Access Gateway
Nov 1, 2022Okta Access Gateway
Nov 1, 2022Okta Access Gateway
Nov 1, 2022OpenSSL v3.0.6 crash vulnerabilities (CVE-2022-3786, CVE-2022-3602)