CVE-2022-2068

CVSS v3.1 9.8 (Critical)
98% Progress
CVSS v2.0 10 (High)
100% Progress
EPSS 12.26 % (96th)
12.26% Progress
Affected Products 43
Advisories 35

In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to prevent command injection were found by code review. When the CVE-2022-1292 was fixed it was not discovered that there are other places in the script where the file names of certificates being hashed were possibly passed to a command executed through the shell. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the c_rehash script is considered obsolete and should be replaced by the OpenSSL rehash command line tool. Fixed in OpenSSL 3.0.4 (Affected 3.0.0,3.0.1,3.0.2,3.0.3). Fixed in OpenSSL 1.1.1p (Affected 1.1.1-1.1.1o). Fixed in OpenSSL 1.0.2zf (Affected 1.0.2-1.0.2ze).

Weaknesses
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Related CVEs
CVE Status
PUBLISHED
CNA
OpenSSL Software Foundation
Published Date
2022-06-21 15:15:09
(2 years ago)
Updated Date
2023-11-07 03:46:11
(10 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Openssl from 1.0.2 version and prior 1.0.2zf version cpe:2.3:a:openssl:openssl >= 1.0.2 < 1.0.2zf
  Openssl from 1.1.1 version and prior 1.1.1p version cpe:2.3:a:openssl:openssl >= 1.1.1 < 1.1.1p
  Openssl from 3.0.0 version and prior 3.0.4 version cpe:2.3:a:openssl:openssl >= 3.0.0 < 3.0.4

Configuration #2

    CPE23 From Up To
  Debian Linux 10.0 cpe:2.3:o:debian:debian_linux:10.0
  Debian Linux 11.0 cpe:2.3:o:debian:debian_linux:11.0

Configuration #3

    CPE23 From Up To
  Fedoraproject Fedora 35 cpe:2.3:o:fedoraproject:fedora:35
  Fedoraproject Fedora 36 cpe:2.3:o:fedoraproject:fedora:36

Configuration #4

    CPE23 From Up To
  Siemens Sinec Ins prior 1.0 version cpe:2.3:a:siemens:sinec_ins < 1.0
  Siemens Sinec Ins 1.0 cpe:2.3:a:siemens:sinec_ins:1.0:-
  Siemens Sinec Ins 1.0 SP1 cpe:2.3:a:siemens:sinec_ins:1.0:sp1
  Siemens Sinec Ins 1.0 SP2 cpe:2.3:a:siemens:sinec_ins:1.0:sp2

Configuration #5

    CPE23 From Up To
  Netapp Element Software cpe:2.3:a:netapp:element_software:-
  Netapp Hci Management Node cpe:2.3:a:netapp:hci_management_node:-
  Netapp Ontap Antivirus Connector cpe:2.3:a:netapp:ontap_antivirus_connector:-
  Netapp Ontap Select Deploy Administration Utility cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-
  Netapp Santricity Smi-s Provider cpe:2.3:a:netapp:santricity_smi-s_provider:-
  Netapp Smi-s Provider cpe:2.3:a:netapp:smi-s_provider:-
  Netapp Snapmanager for Hyper-v cpe:2.3:a:netapp:snapmanager:-:*:*:*:*:hyper-v
  Netapp Solidfire cpe:2.3:a:netapp:solidfire:-

Configuration #6

AND
    CPE23 From Up To
OR  
  Netapp Bootstrap Os cpe:2.3:o:netapp:bootstrap_os:-
OR  
  Running on/with
  Netapp Hci Compute Node cpe:2.3:h:netapp:hci_compute_node:-

Configuration #7

AND
    CPE23 From Up To
OR  
  Netapp H615c Firmware cpe:2.3:o:netapp:h615c_firmware:-
OR  
  Running on/with
  Netapp H615c cpe:2.3:h:netapp:h615c:-

Configuration #8

AND
    CPE23 From Up To
OR  
  Netapp H610s Firmware cpe:2.3:o:netapp:h610s_firmware:-
OR  
  Running on/with
  Netapp H610s cpe:2.3:h:netapp:h610s:-

Configuration #9

AND
    CPE23 From Up To
OR  
  Netapp H610c Firmware cpe:2.3:o:netapp:h610c_firmware:-
OR  
  Running on/with
  Netapp H610c cpe:2.3:h:netapp:h610c:-

Configuration #10

AND
    CPE23 From Up To
OR  
  Netapp H410c Firmware cpe:2.3:o:netapp:h410c_firmware:-
OR  
  Running on/with
  Netapp H410c cpe:2.3:h:netapp:h410c:-

Configuration #11

AND
    CPE23 From Up To
OR  
  Netapp H300s Firmware cpe:2.3:o:netapp:h300s_firmware:-
OR  
  Running on/with
  Netapp H300s cpe:2.3:h:netapp:h300s:-

Configuration #12

AND
    CPE23 From Up To
OR  
  Netapp H500s Firmware cpe:2.3:o:netapp:h500s_firmware:-
OR  
  Running on/with
  Netapp H500s cpe:2.3:h:netapp:h500s:-

Configuration #13

AND
    CPE23 From Up To
OR  
  Netapp H700s Firmware cpe:2.3:o:netapp:h700s_firmware:-
OR  
  Running on/with
  Netapp H700s cpe:2.3:h:netapp:h700s:-

Configuration #14

AND
    CPE23 From Up To
OR  
  Netapp H410s Firmware cpe:2.3:o:netapp:h410s_firmware:-
OR  
  Running on/with
  Netapp H410s cpe:2.3:h:netapp:h410s:-

Configuration #15

AND
    CPE23 From Up To
OR  
  Netapp Fas 8300 Firmware cpe:2.3:o:netapp:fas_8300_firmware:-
OR  
  Running on/with
  Netapp Fas 8300 cpe:2.3:h:netapp:fas_8300:-

Configuration #16

AND
    CPE23 From Up To
OR  
  Netapp Fas 8700 Firmware cpe:2.3:o:netapp:fas_8700_firmware:-
OR  
  Running on/with
  Netapp Fas 8700 cpe:2.3:h:netapp:fas_8700:-

Configuration #17

AND
    CPE23 From Up To
OR  
  Netapp Fas A400 Firmware cpe:2.3:o:netapp:fas_a400_firmware:-
OR  
  Running on/with
  Netapp Fas A400 cpe:2.3:h:netapp:fas_a400:-

Configuration #18

AND
    CPE23 From Up To
OR  
  Netapp Aff 8300 Firmware cpe:2.3:o:netapp:aff_8300_firmware:-
OR  
  Running on/with
  Netapp Aff 8300 cpe:2.3:h:netapp:aff_8300:-

Configuration #19

AND
    CPE23 From Up To
OR  
  Netapp Aff 8700 Firmware cpe:2.3:o:netapp:aff_8700_firmware:-
OR  
  Running on/with
  Netapp Aff 8700 cpe:2.3:h:netapp:aff_8700:-

Configuration #20

AND
    CPE23 From Up To
OR  
  Netapp Aff A400 Firmware cpe:2.3:o:netapp:aff_a400_firmware:-
OR  
  Running on/with
  Netapp Aff A400 cpe:2.3:h:netapp:aff_a400:-

Configuration #21

    CPE23 From Up To
  Broadcom Sannav cpe:2.3:a:broadcom:sannav:-
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...