CVE-2022-2097
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD
Description
AES OCB mode for 32-bit x86 platforms using the AES-NI assembly optimised implementation will not encrypt the entirety of the data under some circumstances. This could reveal sixteen bytes of data that was preexisting in the memory that wasn't written. In the special case of "in place" encryption, sixteen bytes of the plaintext would be revealed. Since OpenSSL does not support OCB based cipher suites for TLS and DTLS, they are both unaffected. Fixed in OpenSSL 3.0.5 (Affected 3.0.0-3.0.4). Fixed in OpenSSL 1.1.1q (Affected 1.1.1-1.1.1p).
Affected (16)
Products: Openssl: Openssl · Fedoraproject: Fedora · Netapp: Active Iq Unified Manager, Clustered Data Ontap Antivirus Connector, H500s Firmware, H700s Firmware, H410s Firmware, H410c Firmware · +2 more
Show all products
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 35 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| All versions |
Configuration D
| Running on/with | Platform Versions |
|---|---|
Netapp H300s Firmware | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp H500s | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp H700s | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp H410s | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp H410c | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.0 |
References (26)
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Source: openssl-security@openssl.org
Source: openssl-security@openssl.org
Mailing ListThird Party Advisory
Source: openssl-security@openssl.org
Source: openssl-security@openssl.org
Source: openssl-security@openssl.org
Source: openssl-security@openssl.org
Third Party Advisory
Source: openssl-security@openssl.org
Source: openssl-security@openssl.org
Source: openssl-security@openssl.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.