CVE-2022-3602 is a buffer overrun vulnerability in OpenSSL versions 3.0.0 through 3.0.6, specifically affecting X.509 certificate verification during name constraint checking. This flaw impacts products like fedoraproject, netapp, and nodejs. With a CVSS score of 7.5 (HIGH), it allows an attacker to trigger a denial of service or potentially remote code execution by crafting a malicious email address in a certificate. While initially critical, mitigating factors like stack overflow protections led to a downgrade to high severity. There is no public exploit code available, nor is it actively exploited, but it has garnered significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.0.0, < 3.0.7CPE matchmatch criteria | cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* | ||
36CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:* | ||
37CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:clustered_data_ontap:-:*:*:*:*:*:*:* | ||
26CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:26:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2022-3602, CVE-2022-3786: OpenSSL Vulnerabilities
Nov 14, 2022CVE-2022-3602, CVE-2022-3786: OpenSSL Vulnerabilities
Nov 14, 2022OpenSSL: CVE-2022-3602 X.509 certificate verification buffer overrun
Nov 8, 2022X.509 Email Address 4-byte Buffer Overflow
Nov 1, 2022Okta Access Gateway Advisory for CVE-2022-3602 and CVE-2022-3786
Nov 1, 2022OpenSSL 3 Vulnerabilities Affecting OpenVPN Products
Nov 1, 2022OpenSSL: X.509 Email Address Buffer Overflow
Nov 1, 2022Splunk’s response to OpenSSL’s CVE-2022-3602 and CVE-2022-3786
Nov 1, 2022Okta Access Gateway
Nov 1, 2022Okta Access Gateway
Nov 1, 2022Okta Access Gateway
Nov 1, 2022OpenSSL v3.0.6 crash vulnerabilities (CVE-2022-3786, CVE-2022-3602)