CVE-2022-1473
Published on: Not Yet Published
Last Modified on: 02/14/2023 12:15:00 PM UTC
Certain versions of A250 from Netapp contain the following vulnerability:
The OPENSSL_LH_flush() function, which empties a hash table, contains a bug that breaks reuse of the memory occuppied by the removed hash table entries. This function is used when decoding certificates or keys. If a long lived process periodically decodes certificates or keys its memory usage will expand without bounds and the process might be terminated by the operating system causing a denial of service. Also traversing the empty hash table entries will take increasingly more time. Typically such long lived processes might be TLS clients or TLS servers configured to accept client certificate authentication. The function was added in the OpenSSL 3.0 version thus older releases are not affected by the issue. Fixed in OpenSSL 3.0.3 (Affected 3.0.0,3.0.1,3.0.2).
- CVE-2022-1473 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
- Affected Vendor/Software:
OpenSSL - OpenSSL version Fixed in OpenSSL 3.0.3 (Affected 3.0.0,3.0.1,3.0.2)
CVSS3 Score: 7.5 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | NONE | NONE | HIGH |
CVSS2 Score: 5 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | LOW | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
NONE | NONE | PARTIAL |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
OpenSSL: Multiple Vulnerabilities (GLSA 202210-02) — Gentoo security | security.gentoo.org text/html |
![]() |
cert-portal.siemens.com application/pdf |
![]() | |
May 2022 OpenSSL Vulnerabilities in NetApp Products | NetApp Product Security | security.netapp.com text/html |
![]() |
www.openssl.org text/plain |
![]() | |
git.openssl.org Git - openssl.git/commitdiff | git.openssl.org text/xml |
![]() |
Related QID Numbers
- 160072 Oracle Enterprise Linux Security Update for Open Secure Sockets Layer (OpenSSL) (ELSA-2022-6224)
- 198771 Ubuntu Security Notification for Open Secure Sockets Layer (OpenSSL) Vulnerabilities (USN-5402-1)
- 240641 Red Hat Update for Open Secure Sockets Layer (OpenSSL) (RHSA-2022:6224)
- 296082 Oracle Solaris 11.4 Support Repository Update (SRU) 48.126.1 Missing (CPUJUL2022)
- 354459 Amazon Linux Security Advisory for Open Secure Sockets Layer (OpenSSL) : ALAS2022-2022-195
- 354511 Amazon Linux Security Advisory for Open Secure Sockets Layer (OpenSSL) : ALAS2022-2022-104
- 354579 Amazon Linux Security Advisory for Open Secure Sockets Layer (OpenSSL) : ALAS-2022-195
- 355250 Amazon Linux Security Advisory for Open Secure Sockets Layer (OpenSSL) : ALAS2023-2023-051
- 501987 Alpine Linux Security Update for Open Secure Sockets Layer3 (OpenSSL3)
- 502415 Alpine Linux Security Update for Open Secure Sockets Layer3 (OpenSSL3)
- 502752 Alpine Linux Security Update for openssl
- 591406 Siemens SIMATIC S7-1500 CPU GNU/Linux subsystem Multiple Vulnerabilities (SSB-439005, ICSA-22-104-13)
- 690862 Free Berkeley Software Distribution (FreeBSD) Security Update for Open Secure Sockets Layer (OpenSSL) (fceb2b08-cb76-11ec-a06f-d4c9ef517024)
- 710638 Gentoo Linux Open Secure Sockets Layer (OpenSSL) Multiple Vulnerabilities (GLSA 202210-02)
- 752308 SUSE Enterprise Linux Security Update for openssl-3 (SUSE-SU-2022:2306-1)
- 940649 AlmaLinux Security Update for Open Secure Sockets Layer (OpenSSL) (ALSA-2022:6224)
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Hardware
| Netapp | A250 | - | All | All | All |
Operating System | Netapp | A250 Firmware | - | All | All | All |
Hardware
| Netapp | A700s | - | All | All | All |
Operating System | Netapp | A700s Firmware | - | All | All | All |
Application | Netapp | Active Iq Unified Manager | - | All | All | All |
Hardware
| Netapp | Aff 500f | - | All | All | All |
Operating System | Netapp | Aff 500f Firmware | - | All | All | All |
Hardware
| Netapp | Aff 8300 | - | All | All | All |
Operating System | Netapp | Aff 8300 Firmware | - | All | All | All |
Hardware
| Netapp | Aff 8700 | - | All | All | All |
Operating System | Netapp | Aff 8700 Firmware | - | All | All | All |
Hardware
| Netapp | Aff A400 | - | All | All | All |
Operating System | Netapp | Aff A400 Firmware | - | All | All | All |
Application | Netapp | Clustered Data Ontap | - | All | All | All |
Application | Netapp | Clustered Data Ontap Antivirus Connector | - | All | All | All |
Hardware
| Netapp | Fabric-attached Storage A400 | - | All | All | All |
Operating System | Netapp | Fabric-attached Storage A400 Firmware | - | All | All | All |
Hardware
| Netapp | Fas 500f | - | All | All | All |
Operating System | Netapp | Fas 500f Firmware | - | All | All | All |
Hardware
| Netapp | Fas 8300 | - | All | All | All |
Operating System | Netapp | Fas 8300 Firmware | - | All | All | All |
Hardware
| Netapp | Fas 8700 | - | All | All | All |
Operating System | Netapp | Fas 8700 Firmware | - | All | All | All |
Hardware
| Netapp | H300e | - | All | All | All |
Operating System | Netapp | H300e Firmware | - | All | All | All |
Hardware
| Netapp | H300s | - | All | All | All |
Operating System | Netapp | H300s Firmware | - | All | All | All |
Hardware
| Netapp | H410s | - | All | All | All |
Operating System | Netapp | H410s Firmware | - | All | All | All |
Hardware
| Netapp | H500e | - | All | All | All |
Operating System | Netapp | H500e Firmware | - | All | All | All |
Hardware
| Netapp | H500s | - | All | All | All |
Operating System | Netapp | H500s Firmware | - | All | All | All |
Hardware
| Netapp | H700e | - | All | All | All |
Operating System | Netapp | H700e Firmware | - | All | All | All |
Hardware
| Netapp | H700s | - | All | All | All |
Operating System | Netapp | H700s Firmware | - | All | All | All |
Application | Netapp | Santricity Smi-s Provider | - | All | All | All |
Application | Netapp | Smi-s Provider | - | All | All | All |
Application | Netapp | Snapmanager | - | All | All | All |
Application | Netapp | Solidfire Enterprise Sds Hci Storage Node | - | All | All | All |
Application | Netapp | Solidfire Hci Management Node | - | All | All | All |
Application | Openssl | Openssl | All | All | All | All |
- cpe:2.3:h:netapp:a250:-:*:*:*:*:*:*:*:
- cpe:2.3:o:netapp:a250_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:netapp:a700s:-:*:*:*:*:*:*:*:
- cpe:2.3:o:netapp:a700s_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vsphere:*:*:
- cpe:2.3:h:netapp:aff_500f:-:*:*:*:*:*:*:*:
- cpe:2.3:o:netapp:aff_500f_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:netapp:aff_8300:-:*:*:*:*:*:*:*:
- cpe:2.3:o:netapp:aff_8300_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:netapp:aff_8700:-:*:*:*:*:*:*:*:
- cpe:2.3:o:netapp:aff_8700_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:netapp:aff_a400:-:*:*:*:*:*:*:*:
- cpe:2.3:o:netapp:aff_a400_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:a:netapp:clustered_data_ontap:-:*:*:*:*:*:*:*:
- cpe:2.3:a:netapp:clustered_data_ontap_antivirus_connector:-:*:*:*:*:*:*:*:
- cpe:2.3:h:netapp:fabric-attached_storage_a400:-:*:*:*:*:*:*:*:
- cpe:2.3:o:netapp:fabric-attached_storage_a400_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:netapp:fas_500f:-:*:*:*:*:*:*:*:
- cpe:2.3:o:netapp:fas_500f_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:netapp:fas_8300:-:*:*:*:*:*:*:*:
- cpe:2.3:o:netapp:fas_8300_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:netapp:fas_8700:-:*:*:*:*:*:*:*:
- cpe:2.3:o:netapp:fas_8700_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:netapp:h300e:-:*:*:*:*:*:*:*:
- cpe:2.3:o:netapp:h300e_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:*:
- cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:*:
- cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:netapp:h500e:-:*:*:*:*:*:*:*:
- cpe:2.3:o:netapp:h500e_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:*:
- cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:netapp:h700e:-:*:*:*:*:*:*:*:
- cpe:2.3:o:netapp:h700e_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:netapp:h700s:-:*:*:*:*:*:*:*:
- cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:a:netapp:santricity_smi-s_provider:-:*:*:*:*:*:*:*:
- cpe:2.3:a:netapp:smi-s_provider:-:*:*:*:*:*:*:*:
- cpe:2.3:a:netapp:snapmanager:-:*:*:*:*:hyper-v:*:*:
- cpe:2.3:a:netapp:solidfire\,_enterprise_sds_\&_hci_storage_node:-:*:*:*:*:*:*:*:
- cpe:2.3:a:netapp:solidfire_\&_hci_management_node:-:*:*:*:*:*:*:*:
- cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*:
Discovery Credit
Aliaksei Levin
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-1292: 影響無し CVE-2022-1343: 影響無し CVE-2022-1434: 影響無し CVE-2022-1473: 影響無し かな。 | 2022-05-03 15:05:39 |
![]() |
CVE-2022-1473 : The OPENSSL_LH_flush function, which empties a hash table, contains a bug that breaks reuse of th… twitter.com/i/web/status/1… | 2022-05-03 15:21:33 |
![]() |
CVE-2022-1473 | 2022-05-03 16:38:22 |
![]() |
Seems Like OPNsense 22.1.6 Really Needs an Update Soon... | 2022-05-05 18:58:28 |
![]() |
CVE-2022-1473, 1434, 1343, 1292 : OpenSSL vulnerabilties patch | 2022-05-18 05:54:01 |