Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-46174

18
FAUCET Score

CVE-2022-46174 is a race condition vulnerability in efs-utils versions v1.34.3 and below, affecting Amazon Elastic File System (EFS) mount helper and the EFS Container Storage Interface (CSI) driver. This medium-severity vulnerability (CVSS 4.2) arises when concurrent TLS mount operations allocate the same local port, potentially leading to failed mounts or incorrect EFS file system mappings. While there is no recommended workaround, the issue is patched in efs-utils v1.34.4. There is no evidence of active exploitation, public exploit code, or inclusion in the KEV catalog, though it has received minimal community and media attention.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.34.4CPE matchmatch criteria
cpe:2.3:a:amazon:efs-utils:*:*:*:*:*:*:*:*
< 1.4.8CPE matchmatch criteria
cpe:2.3:a:amazon:elastic_file_system_container_storage_interface_driver:*:*:*:*:*:go:*:*

CVSS Data

CVSS version used by this source: 3.1

4.2MEDIUM

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
LOW
Exploitability Score
1.6
Impact Score
2.5
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.59%
Probability of exploitation in next 30 days
EPSS Percentile
44.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0059 is in the 35th percentile among its peer group of 1,425 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

github_advisorypatch availablevia nvd_reference
View patch
gopatch availablevia ghsa
Product: github.com/kubernetes-sigs/aws-efs-csi-driverFixed in: 1.4.8
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.12Fixed in: openshift4/ose-aws-efs-csi-driver-container-rhel8:v4.12.0-202301111125.p0.ge59aa10.assembly.stream
View patch
redhatno patchvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4/ose-aws-efs-csi-driver-rhel9-operator

Vendor Advisories (2)

goGHSA-4fv8-w65m-3932medium

efs-utils and aws-efs-csi-driver have race condition during concurrent TLS mounts

Dec 30, 2022
redhatCVE-2022-46174Moderate

aws-efs-utils: Race condition during concurrent TLS mounts in efs-utils and aws-efs-csi-driver

Dec 28, 2022

References

github.com / aws/efs-utils/commit/f3a8f88167d55caa2f78aeb72d4dc1987a9ed62d
PatchThird Party Advisory
github.com / aws/efs-utils/issues/125
Third Party Advisory
github.com / aws/efs-utils/security/advisories/GHSA-4fv8-w65m-3932
Third Party Advisory