CVE-2022-46174 is a race condition vulnerability in efs-utils versions v1.34.3 and below, affecting Amazon Elastic File System (EFS) mount helper and the EFS Container Storage Interface (CSI) driver. This medium-severity vulnerability (CVSS 4.2) arises when concurrent TLS mount operations allocate the same local port, potentially leading to failed mounts or incorrect EFS file system mappings. While there is no recommended workaround, the issue is patched in efs-utils v1.34.4. There is no evidence of active exploitation, public exploit code, or inclusion in the KEV catalog, though it has received minimal community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.34.4CPE matchmatch criteria | cpe:2.3:a:amazon:efs-utils:*:*:*:*:*:*:*:* | ||
< 1.4.8CPE matchmatch criteria | cpe:2.3:a:amazon:elastic_file_system_container_storage_interface_driver:*:*:*:*:*:go:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.