CVE-2022-27775
Published on: Not Yet Published
Last Modified on: 01/05/2023 06:08:00 PM UTC
Certain versions of Fabric Operating System from Brocade contain the following vulnerability:
An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it could reuse a connection instead.
- CVE-2022-27775 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
CVSS3 Score: 7.5 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | NONE | NONE |
CVSS2 Score: 5 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | LOW | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | NONE | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
curl: Multiple Vulnerabilities (GLSA 202212-01) — Gentoo security | security.gentoo.org text/html |
![]() |
HackerOne | hackerone.com text/html |
![]() |
Debian -- Security Information -- DSA-5197-1 curl | www.debian.org Depreciated Link text/html |
![]() |
May 2022 Libcurl Vulnerabilities in NetApp Products | NetApp Product Security | security.netapp.com text/html |
![]() |
Related QID Numbers
- 160308 Oracle Enterprise Linux Security Update for curl (ELSA-2022-8299)
- 180909 Debian Security Update for curl (DSA 5197-1)
- 198759 Ubuntu Security Notification for curl Vulnerabilities (USN-5397-1)
- 240890 Red Hat Update for curl (RHSA-2022:8299)
- 282695 Fedora Security Update for curl (FEDORA-2022-3d8f00cde2)
- 282723 Fedora Security Update for curl (FEDORA-2022-3517572083)
- 282754 Fedora Security Update for curl (FEDORA-2022-8277bef335)
- 296082 Oracle Solaris 11.4 Support Repository Update (SRU) 48.126.1 Missing (CPUJUL2022)
- 353292 Amazon Linux Security Advisory for curl : ALAS2-2022-1792
- 354277 Amazon Linux Security Advisory for curl : ALAS2022-2022-055
- 354292 Amazon Linux Security Advisory for curl : ALAS2022-2022-206
- 354341 Amazon Linux Security Advisory for curl : ALAS2022-2022-065
- 354587 Amazon Linux Security Advisory for curl : ALAS-2022-206
- 355207 Amazon Linux Security Advisory for curl : ALAS2023-2023-083
- 500138 Alpine Linux Security Update for curl
- 501954 Alpine Linux Security Update for curl
- 502212 Alpine Linux Security Update for curl
- 591406 Siemens SIMATIC S7-1500 CPU GNU/Linux subsystem Multiple Vulnerabilities (SSB-439005, ICSA-22-104-13)
- 671910 EulerOS Security Update for curl (EulerOS-SA-2022-1961)
- 671934 EulerOS Security Update for curl (EulerOS-SA-2022-1991)
- 671963 EulerOS Security Update for curl (EulerOS-SA-2022-2153)
- 671972 EulerOS Security Update for curl (EulerOS-SA-2022-2128)
- 690855 Free Berkeley Software Distribution (FreeBSD) Security Update for curl (92a4d881-c6cf-11ec-a06f-d4c9ef517024)
- 710693 Gentoo Linux curl Multiple Vulnerabilities (GLSA 202212-01)
- 752123 SUSE Enterprise Linux Security Update for curl (SUSE-SU-2022:1657-1)
- 902163 Common Base Linux Mariner (CBL-Mariner) Security Update for curl (9880)
- 902168 Common Base Linux Mariner (CBL-Mariner) Security Update for curl (9880-1)
- 902551 Common Base Linux Mariner (CBL-Mariner) Security Update for curl (9880)
- 940789 AlmaLinux Security Update for curl (ALSA-2022:8299)
- 960552 Rocky Linux Security Update for curl (RLSA-2022:8299)
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Operating System | Brocade | Fabric Operating System | - | All | All | All |
Operating System | Debian | Debian Linux | 11.0 | All | All | All |
Application | Haxx | Curl | All | All | All | All |
Application | Netapp | Clustered Data Ontap | - | All | All | All |
Hardware
| Netapp | H300s | - | All | All | All |
Operating System | Netapp | H300s Firmware | - | All | All | All |
Hardware
| Netapp | H410s | - | All | All | All |
Operating System | Netapp | H410s Firmware | - | All | All | All |
Hardware
| Netapp | H500s | - | All | All | All |
Operating System | Netapp | H500s Firmware | - | All | All | All |
Hardware
| Netapp | H700s | - | All | All | All |
Operating System | Netapp | H700s Firmware | - | All | All | All |
Operating System | Netapp | Hci Bootstrap Os | - | All | All | All |
Hardware
| Netapp | Hci Compute Node | - | All | All | All |
Application | Netapp | Solidfire Hci Management Node | - | All | All | All |
Application | Netapp | Solidfire Hci Storage Node | - | All | All | All |
- cpe:2.3:o:brocade:fabric_operating_system:-:*:*:*:*:*:*:*:
- cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*:
- cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*:
- cpe:2.3:a:netapp:clustered_data_ontap:-:*:*:*:*:*:*:*:
- cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:*:
- cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:*:
- cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:*:
- cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:h:netapp:h700s:-:*:*:*:*:*:*:*:
- cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*:
- cpe:2.3:o:netapp:hci_bootstrap_os:-:*:*:*:*:*:*:*:
- cpe:2.3:h:netapp:hci_compute_node:-:*:*:*:*:*:*:*:
- cpe:2.3:a:netapp:solidfire_\&_hci_management_node:-:*:*:*:*:*:*:*:
- cpe:2.3:a:netapp:solidfire_\&_hci_storage_node:-:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-27775 Bad local IPv6 connection reuse is curl using the wrong connection for reuse if IPv6 zone id is used… twitter.com/i/web/status/1… | 2022-04-27 06:35:01 |
![]() |
Project curl Security Advisory, April 27 2022: Bad local IPv6 connection reuse curl.se/docs/CVE-2022-… https://t.co/33XvR1yn71 | 2022-04-27 07:24:14 |
![]() |
HackerOne Bug Bounty Disclosure: cve-2022-27775:-bad-local-ipv6-connection-reusebynyymi - redpacketsecurity.com/hackerone-bugb… | 2022-04-27 17:02:11 |
![]() |
cve.report/CVE-2022-27775 An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable tha… twitter.com/i/web/status/1… | 2022-06-02 16:34:57 |
![]() |
Curl - CVE-2022-27775: hackerone.com/reports/1546268 | 2022-06-02 17:00:12 |
![]() |
Seems Like OPNsense 22.1.6 Really Needs an Update Soon... | 2022-05-05 18:58:28 |
![]() |
DSM Version: 7.2-64561 | 2023-05-22 03:16:44 |