Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-2097

22
FAUCET Score

CVE-2022-2097 describes a flaw in OpenSSL's AES OCB mode implementation on 32-bit x86 platforms utilizing AES-NI, where some data may not be encrypted, potentially revealing sixteen bytes of pre-existing memory or plaintext in "in place" encryption scenarios. This affects OpenSSL versions 3.0.0-3.0.4 and 1.1.1-1.1.1p, as well as products like Debian, Fedora, NetApp, and Siemens. The vulnerability has a CVSS score of 5.3 (Medium), indicating a network-based attack with low complexity and a potential impact of low confidentiality, but no integrity or availability impact. There is currently no evidence of active exploitation, no public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion, with no media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.1.1, < 1.1.1qCPE matchmatch criteria
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
>= 3.0.0, < 3.0.5CPE matchmatch criteria
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
35CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
36CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*

CVSS Data

CVSS version used by this source: 3.1

5.3MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
4.42%
Probability of exploitation in next 30 days
EPSS Percentile
90.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0442 is in the 87th percentile among its peer group of 23,725 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (31)

angularpatch availablevia llm_extracted
ffmpegpatch availablevia llm_extracted
githubpatch availablevia llm_extracted
View patch
halopatch availablevia llm_extracted
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 1.1.1k-20
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 x64Fixed in: 20240223gitedc6681206c1-2
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 x64Fixed in: 1.0.1-2
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 ARMFixed in: 20240223gitedc6681206c1-2
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 ARMFixed in: 1.0.1-2
microsoftpatch availablevia msrc
Product: 19915-17084Fixed in: 1.0.1-2
microsoftpatch availablevia msrc
Product: 18666-17084Fixed in: 1.0.1-2
microsoftpatch availablevia msrc
Product: 17859-17084Fixed in: 20240223gitedc6681206c1-2
microsoftpatch availablevia msrc
Product: 18664-16820Fixed in: 1.1.1k-12
microsoftpatch availablevia msrc
Product: 18665-16823Fixed in: 1.1.1k-20
microsoftpatch availablevia msrc
Product: 18131-17084Fixed in: 20240223gitedc6681206c1-1
microsoftpatch availablevia msrc
Product: azl3 edk2 20240223gitedc6681206c1-1 on Azure Linux 3.0Fixed in: 20240223gitedc6681206c1-1
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 x64Fixed in: 1.1.1k-12
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 ARMFixed in: 1.1.1k-12
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 1.1.1k-20
microsoftpatch availablevia msrc
Product: azl3 hvloader 1.0.1-1 on Azure Linux 3.0Fixed in: 1.0.1-2
microsoftpatch availablevia msrc
Product: azl3 hvloader 1.0.1-2 on Azure Linux 3.0Fixed in: 1.0.1-2
microsoftpatch availablevia msrc
Product: azl3 edk2 20230301gitf80f052277c8-37 on Azure Linux 3.0Fixed in: 20240223gitedc6681206c1-2
microsoftpatch availablevia msrc
Product: cm1 openssl 1.1.1k-12 on CBL Mariner 1.0Fixed in: 1.1.1k-12
microsoftpatch availablevia msrc
Product: cbl2 openssl 1.1.1k-20 on CBL Mariner 2.0Fixed in: 1.1.1k-20
planepatch availablevia llm_extracted
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: openssl-1:1.1.1k-7.el8_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: openssl-1:3.0.1-41.el9_0
View patch
rustpatch availablevia ghsa
Product: openssl-srcFixed in: 300.0.9
rustpatch availablevia ghsa
Product: openssl-srcFixed in: 111.22.0
wso2patch availablevia llm_extracted
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: compat-openssl11

Vendor Advisories (10)

microsoft2024-Sep/CVE-2022-2097

CVE-2022-2097

Sep 10, 2024
githubllm-github-e0092fd6944429a1MEDIUM

AS-2022-009: OpenSSL

Aug 29, 2022
microsoft2022-Jul/CVE-2022-2097Moderate

AES OCB fails to encrypt some bytes

Jul 12, 2022
rustGHSA-3wx7-46ch-7rq2high

AES OCB fails to encrypt some bytes

Jul 6, 2022
redhatCVE-2022-2097Moderate

openssl: AES OCB fails to encrypt some bytes

Jul 5, 2022
planellm-plane-51107e822629f61fHIGH

OpenSSL Vulnerabilities

ffmpegllm-ffmpeg-15347a436b10d352HIGH

OpenSSL Vulnerabilities Fixed

wso2llm-wso2-3bfa581022ac1c83

OpenSSL Vulnerabilities

angularllm-angular-bfbc3de9673ae177

OpenSSL Vulnerabilities

halollm-halo-97bc06c9d09e368b

OpenSSL Vulnerabilities

References

cert-portal.siemens.com / productcert/pdf/ssa-332410.pdf
Third Party Advisory
git.openssl.org / gitweb
git.openssl.org / gitweb
lists.debian.org / debian-lts-announce/2023/02/msg00019.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/R6CK57NBQFTPUMXAPJURCGXUYT76NQAK
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/V6567JERRHHJW2GNGJGKDRNHR7SNPZK7
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/VCMNWKERPBKOEBNL7CLTTX3ZZCZLH7XA
security.gentoo.org / glsa/202210-02
Third Party Advisory
security.netapp.com / advisory/ntap-20220715-0011
Third Party Advisory
security.netapp.com / advisory/ntap-20230420-0008
security.netapp.com / advisory/ntap-20240621-0006
debian.org / security/2023/dsa-5343
Third Party Advisory
openssl.org / news/secadv/20220705.txt
Vendor Advisory