CVE-2022-1343 is a vulnerability in OpenSSL versions 3.0.0 through 3.0.2, affecting the OCSP_basic_verify function. When the non-default OCSP_NOCHECKS flag is used, this function incorrectly reports a successful verification of an OCSP response even if the signer certificate verification fails. This issue also impacts the OpenSSL "ocsp" command-line application when using the "-no_cert_checks" option. The vulnerability has a CVSS v3.1 score of 5.3 (Medium), indicating a network-based attack with low complexity and no user interaction required, leading to a potential integrity impact. The primary concern is that an application might incorrectly trust a compromised OCSP response. Currently, there is no evidence of active exploitation, nor are there publicly available exploit codes in Metasploit, Nuclei, or ExploitDB. Community discussion is minimal, with only one mention identified, and there is no media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.0.0, < 3.0.3CPE matchmatch criteria | cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vsphere:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:clustered_data_ontap:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:clustered_data_ontap_antivirus_connector:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:santricity_smi-s_provider:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
AS-2022-007: OpenSSL
May 30, 2022`OCSP_basic_verify` may incorrectly verify the response signing certificate
May 4, 2022openssl: Signer certificate verification returns inaccurate response when using OCSP_NOCHECKS
May 3, 2022