CVE-2022-26083

CWE-12045 documents5 sources
Severity
7.5HIGH
EPSS
0.1%
top 68.07%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 14

Description

Generation of weak initialization vector in an Intel(R) IPP Cryptography software library before version 2021.5 may allow an unauthenticated user to potentially enable information disclosure via local access.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:NExploitability: 1.1 | Impact: 5.8

Affected Packages2 packages

🔴Vulnerability Details

2
CVEList
CVE-2022-26083: Generation of weak initialization vector in an Intel(R) IPP Cryptography software library before version 20212025-02-14
GHSA
GHSA-97m5-x73g-j7xj: Generation of weak initialization vector in an Intel(R) IPP Cryptography software library before version 20212025-02-14

📋Vendor Advisories

1
Debian
CVE-2022-26083: ipp-crypto - Generation of weak initialization vector in an Intel(R) IPP Cryptography softwar...2022
CVE-2022-26083 (HIGH CVSS 7.5) | Generation of weak initialization v | cvebase.io