CVE-2022-2097 describes a flaw in OpenSSL's AES OCB mode implementation on 32-bit x86 platforms utilizing AES-NI, where some data may not be encrypted, potentially revealing sixteen bytes of pre-existing memory or plaintext in "in place" encryption scenarios. This affects OpenSSL versions 3.0.0-3.0.4 and 1.1.1-1.1.1p, as well as products like Debian, Fedora, NetApp, and Siemens. The vulnerability has a CVSS score of 5.3 (Medium), indicating a network-based attack with low complexity and a potential impact of low confidentiality, but no integrity or availability impact. There is currently no evidence of active exploitation, no public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion, with no media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.1.1, < 1.1.1qCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* | ||
>= 3.0.0, < 3.0.5CPE matchmatch criteria | cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* | ||
35CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* | ||
36CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2022-2097
Sep 10, 2024AS-2022-009: OpenSSL
Aug 29, 2022AES OCB fails to encrypt some bytes
Jul 12, 2022AES OCB fails to encrypt some bytes
Jul 6, 2022openssl: AES OCB fails to encrypt some bytes
Jul 5, 2022OpenSSL Vulnerabilities
OpenSSL Vulnerabilities Fixed
OpenSSL Vulnerabilities
OpenSSL Vulnerabilities
OpenSSL Vulnerabilities