CVE-2022-2274
Last modified
CVE-2022-2274 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. The OpenSSL 3.0.4 release introduced a serious bug in the RSA implementation for X86_64 CPUs supporting the AVX512IFMA instructions. This issue makes the RSA implementation with 2048 bit private keys incorrect on such machines and memory corruption will happen during the computation. EPSS estimates a 36.51% chance of exploitation in the next 30 days.
Description
The OpenSSL 3.0.4 release introduced a serious bug in the RSA implementation for X86_64 CPUs supporting the AVX512IFMA instructions. This issue makes the RSA implementation with 2048 bit private keys incorrect on such machines and memory corruption will happen during the computation. As a consequence of the memory corruption an attacker may be able to trigger a remote code execution on the machine performing the computation. SSL/TLS servers or other servers using 2048 bit RSA private keys running on machines supporting AVX512IFMA instructions of the X86_64 architecture are affected by this issue.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Openssl | Openssl | 3.0.4 |
| Netapp | Snapcenter | All versions |
| Netapp | H410c Firmware | All versions |
| Netapp | H300s Firmware | All versions |
| Netapp | H500s Firmware | All versions |
| Netapp | H700s Firmware | All versions |
| Netapp | H410s Firmware | All versions |
References
- https://github.com/openssl/openssl/issues/18625Exploit, Issue Tracking, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220715-0010/Third Party Advisory
- https://www.openssl.org/news/secadv/20220705.txtVendor Advisory
- https://github.com/openssl/openssl/issues/18625Exploit, Issue Tracking, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220715-0010/Third Party Advisory
- https://www.openssl.org/news/secadv/20220705.txtVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-2274?
How severe is CVE-2022-2274?
How do I fix CVE-2022-2274?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-22734The Simple Quotation WordPress plugin through 1.3.2 does not…6.1
- CVE-2022-22735The Simple Quotation WordPress plugin through 1.3.2 does not…8.8
- CVE-2022-22736If Firefox was installed to a world-writable directory, a lo…7
- CVE-2022-22737Constructing audio sinks could have lead to a race condition…7.5
- CVE-2022-22738Applying a CSS filter effect could have accessed out of boun…8.8
- CVE-2022-22739Malicious websites could have tricked users into accepting l…6.5
- CVE-2022-22740Certain network request objects were freed too early when re…8.8
- CVE-2022-22741When resizing a popup while requesting fullscreen access, th…7.5
- CVE-2022-22742When inserting text while in edit mode, some characters migh…6.5
- CVE-2022-22743When navigating from inside an iframe while requesting fulls…4.3
- CVE-2022-22744The constructed curl command from the "Copy as curl" feature…8.8
- CVE-2022-22745Securitypolicyviolation events could have leaked cross-origi…6.5
Are you affected by CVE-2022-2274?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
