CVE-2022-2274 is a critical memory corruption vulnerability in OpenSSL 3.0.4's RSA implementation, specifically affecting X86_64 CPUs with AVX512IFMA instructions when using 2048-bit RSA private keys. This flaw can lead to remote code execution on affected SSL/TLS servers and other systems utilizing OpenSSL, with NetApp also listed as an affected product. With a CVSS score of 9.8 (Critical) and an EPSS score indicating high exploitability potential, the vulnerability presents a significant risk due to its network-based attack vector and low attack complexity. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered community attention and media coverage, suggesting awareness among potential attackers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.0.4CPE matchmatch criteria | cpe:2.3:a:openssl:openssl:3.0.4:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:snapcenter:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remote Memory Corruption Vulnerability in OpenSSL
Oct 31, 2022Remote Memory Corruption Vulnerability in OpenSSL
Oct 31, 2022Remote Memory Corruption Vulnerability in OpenSSL
Oct 31, 2022Remote Memory Corruption Vulnerability in OpenSSL
Oct 31, 2022Remote Memory Corruption Vulnerability in OpenSSL
Oct 31, 2022Remote Memory Corruption Vulnerability in OpenSSL
Oct 31, 2022Remote Memory Corruption Vulnerability in OpenSSL
Oct 31, 2022Remote Memory Corruption Vulnerability in OpenSSL
Oct 31, 2022openssl-src heap memory corruption with RSA private key operation
Jul 2, 2022openssl: AVX-512-specific heap buffer overflow
Jun 22, 2022