CVE-2022-1292
high · 7.3The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the c_rehash script is considered obsolete and should be replaced by the OpenSSL rehash command line tool. Fixed in OpenSSL 3.0.3 (Affected 3.0.0,3.0.1,3.0.2). Fixed in OpenSSL 1.1.1o (Affected 1.1.1-1.1.1n). Fixed in OpenSSL 1.0.2ze (Affected 1.0.2-1.0.2zd).
7.3
CVSS
82.6%
EPSS (exploit prob.)
100th
EPSS percentile
2022-05-03
Published
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Weaknesses
CWE-78
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| siemens | brownfield_connectivity_gateway | < 2.15 |
| openssl | openssl | >= 1.0.2, < 1.0.2ze |
| openssl | openssl | >= 1.1.1, < 1.1.1o |
| openssl | openssl | >= 3.0.0, < 3.0.3 |
| debian | debian_linux | 9.0 |
| debian | debian_linux | 10.0 |
| debian | debian_linux | 11.0 |
| netapp | active_iq_unified_manager | all versions |
| netapp | active_iq_unified_manager | all versions |
| netapp | active_iq_unified_manager | all versions |
| netapp | clustered_data_ontap | all versions |
| netapp | clustered_data_ontap_antivirus_connector | all versions |
| netapp | oncommand_insight | all versions |
| netapp | oncommand_workflow_automation | all versions |
| netapp | santricity_smi-s_provider | all versions |
| netapp | smi-s_provider | all versions |
| netapp | snapcenter | all versions |
| netapp | snapmanager | all versions |
| netapp | solidfire,_enterprise_sds_&_hci_storage_node | all versions |
| netapp | solidfire_&_hci_management_node | all versions |
| netapp | a700s_firmware | all versions |
| netapp | a700s | all versions |
| netapp | h300s_firmware | all versions |
| netapp | h300s | all versions |
| netapp | h500s_firmware | all versions |
| netapp | h500s | all versions |
| netapp | h700s_firmware | all versions |
| netapp | h700s | all versions |
| netapp | h300e_firmware | all versions |
| netapp | h300e | all versions |
| netapp | h500e_firmware | all versions |
| netapp | h500e | all versions |
| netapp | h700e_firmware | all versions |
| netapp | h700e | all versions |
| netapp | h410s_firmware | all versions |
| netapp | h410s | all versions |
| netapp | aff_8300_firmware | all versions |
| netapp | aff_8300 | all versions |
| netapp | fas_8300_firmware | all versions |
| netapp | fas_8300 | all versions |
Check a specific version with /api/v1/cve/match.
References
- https://cert-portal.siemens.com/productcert/pdf/ssa-953464.pdf
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=1ad73b4d27bd8c1b369a3cd453681d3a4f1bb9b2
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=548d3f280a6e737673f5b61fce24bb100108dfeb
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=e5fd1728ef4c7a5bf7c7a7163ca60370460a6e23
- https://lists.debian.org/debian-lts-announce/2022/05/msg00019.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VX4KWHPMKYJL6ZLW4M5IU7E5UV5ZWJQU/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZNU5M7BXMML26G3GPYKFGQYPQDRSNKDD/
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0011
- https://security.gentoo.org/glsa/202210-02
- https://security.netapp.com/advisory/ntap-20220602-0009/
- https://security.netapp.com/advisory/ntap-20220729-0004/
- https://www.debian.org/security/2022/dsa-5139
- https://www.openssl.org/news/secadv/20220503.txt
- https://www.oracle.com/security-alerts/cpujul2022.html
- https://cert-portal.siemens.com/productcert/pdf/ssa-953464.pdf
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=1ad73b4d27bd8c1b369a3cd453681d3a4f1bb9b2
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=548d3f280a6e737673f5b61fce24bb100108dfeb
- https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=e5fd1728ef4c7a5bf7c7a7163ca60370460a6e23
- https://gitlab.com/fraf0/cve-2022-1292-re_score-analysis
- https://lists.debian.org/debian-lts-announce/2022/05/msg00019.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VX4KWHPMKYJL6ZLW4M5IU7E5UV5ZWJQU/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZNU5M7BXMML26G3GPYKFGQYPQDRSNKDD/
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0011
- https://security.gentoo.org/glsa/202210-02
- https://security.netapp.com/advisory/ntap-20220602-0009/
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2022-1292