Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-2274

57
FAUCET Score

CVE-2022-2274 is a critical memory corruption vulnerability in OpenSSL 3.0.4's RSA implementation, specifically affecting X86_64 CPUs with AVX512IFMA instructions when using 2048-bit RSA private keys. This flaw can lead to remote code execution on affected SSL/TLS servers and other systems utilizing OpenSSL, with NetApp also listed as an affected product. With a CVSS score of 9.8 (Critical) and an EPSS score indicating high exploitability potential, the vulnerability presents a significant risk due to its network-based attack vector and low attack complexity. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered community attention and media coverage, suggesting awareness among potential attackers.

Impacted Technologies

VendorProductVersion(s)CPE
3.0.4CPE matchmatch criteria
cpe:2.3:a:openssl:openssl:3.0.4:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:netapp:snapcenter:-:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
44.88%
Probability of exploitation in next 30 days
EPSS Percentile
98.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.4488 is in the 96th percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (9)

rustpatch availablevia ghsa
Product: openssl-srcFixed in: 300.0.9
barracudavendor investigatingvia llm_extracted
boschvendor investigatingvia llm_extracted
clamavvendor investigatingvia llm_extracted
consulvendor investigatingvia llm_extracted
freshrssvendor investigatingvia llm_extracted
qdrantvendor investigatingvia llm_extracted
symantecvendor investigatingvia llm_extracted
verbbvendor investigatingvia llm_extracted

Vendor Advisories (10)

qdrantllm-qdrant-160624309bb406b6

Remote Memory Corruption Vulnerability in OpenSSL

Oct 31, 2022
boschllm-bosch-0ffed77e2e20ae79

Remote Memory Corruption Vulnerability in OpenSSL

Oct 31, 2022
freshrssllm-freshrss-67dff7b36df2b1b4

Remote Memory Corruption Vulnerability in OpenSSL

Oct 31, 2022
barracudallm-barracuda-200687851e8d2ffa

Remote Memory Corruption Vulnerability in OpenSSL

Oct 31, 2022
symantecllm-symantec-e793f78238d527ed

Remote Memory Corruption Vulnerability in OpenSSL

Oct 31, 2022
verbbllm-verbb-25bdba671fefd821

Remote Memory Corruption Vulnerability in OpenSSL

Oct 31, 2022
consulllm-consul-7b559fb70b8e5fd2

Remote Memory Corruption Vulnerability in OpenSSL

Oct 31, 2022
clamavllm-clamav-025491b9967b8270

Remote Memory Corruption Vulnerability in OpenSSL

Oct 31, 2022
rustGHSA-735f-pg76-fxc4critical

openssl-src heap memory corruption with RSA private key operation

Jul 2, 2022
redhatCVE-2022-2274Important

openssl: AVX-512-specific heap buffer overflow

Jun 22, 2022

References

github.com / openssl/openssl/issues/18625
ExploitIssue TrackingThird Party Advisory
git.openssl.org / gitweb
security.netapp.com / advisory/ntap-20220715-0010
Third Party Advisory
openssl.org / news/secadv/20220705.txt
Vendor Advisory