CVE-2022-4203
published 2023-02-24CVE-2022-4203: A read buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate…
PriorityP424medium4.9CVSS 3.1
AVNACLPRHUINSUCNINAH
EPSS
1.48%
71.0th percentile
A read buffer overrun can be triggered in X.509 certificate verification,
specifically in name constraint checking. Note that this occurs
after certificate chain signature verification and requires either a
CA to have signed the malicious certificate or for the application to
continue certificate verification despite failure to construct a path
to a trusted issuer.
The read buffer overrun might result in a crash which could lead to
a denial of service attack. In theory it could also result in the disclosure
of private memory contents (such as private keys, or sensitive plaintext)
although we are not aware of any working exploit leading to memory
contents disclosure as of the time of release of this advisory.
In a TLS client, this can be triggered by connecting to a malicious
server. In a TLS server, this can be triggered if the server requests
client authentication and a malicious client connects.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openssl | < openssl 3.0.8-1 (bookworm) | openssl 3.0.8-1 (bookworm) |
| openssl | openssl | >= 0 < 3.0.8-r0 | 3.0.8-r0 |
| openssl | openssl | >= 0 < 3.0.8-r0 | 3.0.8-r0 |
| openssl | openssl | >= 0 < 3.0.8-r0 | 3.0.8-r0 |
| openssl | openssl | >= 0 < 3.0.8-r0 | 3.0.8-r0 |
| openssl | openssl | >= 0 < 3.0.8-r0 | 3.0.8-r0 |
| openssl | openssl | >= 0 < 3.0.8-r0 | 3.0.8-r0 |
| openssl | openssl | >= 0 < 3.0.8-r0 | 3.0.8-r0 |
| openssl | openssl | >= 0 < 3.0.8-1 | 3.0.8-1 |
| openssl | openssl | >= 0 < 3.0.8-1 | 3.0.8-1 |
| openssl | openssl | >= 0 < 3.0.8-1 | 3.0.8-1 |
| openssl | openssl | >= 0 < 1.1.1-1ubuntu2.1~18.04.21 | 1.1.1-1ubuntu2.1~18.04.21 |
| openssl | openssl | >= 0 < 1.1.1f-1ubuntu2.17 | 1.1.1f-1ubuntu2.17 |
| openssl | openssl | >= 0 < 3.0.2-0ubuntu1.8 | 3.0.2-0ubuntu1.8 |
| openssl | openssl | >= 3.0.0 < 3.0.8 | 3.0.8 |
| paloalto | cortex_data | — | — |
| paloalto | cortex_xdr | — | — |
| paloalto | cortex_xpanse | — | — |
| paloalto | cortex_xsoar | — | — |
| paloalto | globalprotect | — | — |
| paloalto | pan-os | — | — |
| paloalto | prisma_access | — | — |
| paloalto | prisma_cloud | — | — |
| paloalto | prisma_sd | — | — |
CVSS provenance
nvdv3.14.9MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
osv4.9MEDIUM
vendor_debian4.9MEDIUM
vendor_redhat4.9MEDIUM
vendor_ubuntu4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2022-4203: A read buffer overrun can be triggered in X
osv·2023-02-24·CVSS 4.9
CVE-2022-4203 [MEDIUM] CVE-2022-4203: A read buffer overrun can be triggered in X
A read buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification and requires either a CA to have signed the malicious certificate or for the application to continue certificate verification despite failure to construct a path to a trusted issuer. The read buffer overrun might result in a crash which could lead to a denial of service attack. In theory it could also result in the disclosure of private memory contents (such as private keys, or sensitive plaintext) although we are not aware of any working exploit leading to memory contents disclosure as of the time of release of this advisory. In a TLS client, this can be triggered by connecting to a malicious server. In a T
OSV
CVE-2022-4203: A read buffer overrun can be triggered in X
osv·2023-02-24·CVSS 4.9
CVE-2022-4203 [MEDIUM] CVE-2022-4203: A read buffer overrun can be triggered in X
A read buffer overrun can be triggered in X.509 certificate verification,
specifically in name constraint checking. Note that this occurs
after certificate chain signature verification and requires either a
CA to have signed the malicious certificate or for the application to
continue certificate verification despite failure to construct a path
to a trusted issuer.
The read buffer overrun might result in a crash which could lead to
a denial of service attack. In theory it could also result in the disclosure
of private memory contents (such as private keys, or sensitive plaintext)
although we are not aware of any working exploit leading to memory
contents disclosure as of the time of release of this advisory.
In a TLS client, this can be triggered by connecting to a malicious
server. In a
GHSA
openssl-src contains Read Buffer Overflow in X.509 Name Constraint
ghsa·2023-02-08
CVE-2022-4203 [CRITICAL] CWE-125 openssl-src contains Read Buffer Overflow in X.509 Name Constraint
openssl-src contains Read Buffer Overflow in X.509 Name Constraint
A read buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs
after certificate chain signature verification and requires either a CA to have signed the malicious certificate or for the application to
continue certificate verification despite failure to construct a path to a trusted issuer.
The read buffer overrun might result in a crash which could lead to a denial of service attack. In theory it could also result in the disclosure of private memory contents (such as private keys, or sensitive plaintext) although we are not aware of any working exploit leading to memory contents disclosure as of the time of release of this advisory.
In a TLS cli
OSV
openssl-src contains Read Buffer Overflow in X.509 Name Constraint
osv·2023-02-08
CVE-2022-4203 [CRITICAL] openssl-src contains Read Buffer Overflow in X.509 Name Constraint
openssl-src contains Read Buffer Overflow in X.509 Name Constraint
A read buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs
after certificate chain signature verification and requires either a CA to have signed the malicious certificate or for the application to
continue certificate verification despite failure to construct a path to a trusted issuer.
The read buffer overrun might result in a crash which could lead to a denial of service attack. In theory it could also result in the disclosure of private memory contents (such as private keys, or sensitive plaintext) although we are not aware of any working exploit leading to memory contents disclosure as of the time of release of this advisory.
In a TLS cli
OSV
openssl vulnerabilities
osv·2023-02-07·CVSS 4.9
CVE-2023-0286 [MEDIUM] openssl vulnerabilities
openssl vulnerabilities
David Benjamin discovered that OpenSSL incorrectly handled X.400 address
processing. A remote attacker could possibly use this issue to read
arbitrary memory contents or cause OpenSSL to crash, resulting in a denial
of service. (CVE-2023-0286)
Corey Bonnell discovered that OpenSSL incorrectly handled X.509 certificate
verification. A remote attacker could possibly use this issue to cause
OpenSSL to crash, resulting in a denial of service. This issue only
affected Ubuntu 22.04 LTS and Ubuntu 22.10. (CVE-2022-4203)
Hubert Kario discovered that OpenSSL had a timing based side channel in the
OpenSSL RSA Decryption implementation. A remote attacker could possibly use
this issue to recover sensitive information. (CVE-2022-4304)
Dawei Wang discovered that OpenSSL incor
OSV
X.509 Name Constraints Read Buffer Overflow
osv·2023-02-07
CVE-2022-4203 X.509 Name Constraints Read Buffer Overflow
X.509 Name Constraints Read Buffer Overflow
A read buffer overrun can be triggered in X.509 certificate verification,
specifically in name constraint checking. Note that this occurs
after certificate chain signature verification and requires either a
CA to have signed the malicious certificate or for the application to
continue certificate verification despite failure to construct a path
to a trusted issuer.
The read buffer overrun might result in a crash which could lead to
a denial of service attack. In theory it could also result in the disclosure
of private memory contents (such as private keys, or sensitive plaintext)
although we are not aware of any working exploit leading to memory
contents disclosure as of the time of release of this advisory.
In a TLS client, this can be trigge
CISA ICS
Hitachi Energy PCU400
cisa_ics·2025-03-06
Hitachi Energy PCU400
ICS Advisory
##
Hitachi Energy PCU400
Release DateMarch 06, 2025
Alert CodeICSA-25-065-01
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.5
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Hitachi Energy
- Equipment: PCU400, PCULogger
- Vulnerabilities: Access of Resource Using Incompatible Type ('Type Confusion'), NULL Pointer Dereference, Use After Free, Double Free, Observable Discrepancy, Out-of-bounds Read
## 2. RISK EVALUATION
Exploitation of these vulnerabilities could allow an attacker to access or decrypt sensitive data, crash the device application, or cause a denial-of-service condition.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Hita
CISA ICS
Siemens SINEC NMS
cisa_ics·2024-02-15
Siemens SINEC NMS
ICS Advisory
##
Siemens SINEC NMS
Release DateFebruary 15, 2024
Alert CodeICSA-24-046-15
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEC NMS
- Vulnerabilities: Out-of-bounds Read, Inadequate Encryption Strength, Double Free, Use After Free, NULL Pointer Dereference, Improper Input Validation, Missing Encryption of Sensitive Data, Allocation of Resources Wit
CISA ICS
Siemens SCALANCE Family Products
cisa_ics·2023-11-16
Siemens SCALANCE Family Products
ICS Advisory
##
Siemens SCALANCE Family Products
Release DateNovember 16, 2023
Alert CodeICSA-23-320-08
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.1
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SCALANCE XB-200/XC-200/XP-200/XF-200BA/XR-300WG Family
- Vulnerabilities: Out-of-bounds Read, Inadequate Encryption Strength, Double Free, NULL Pointer Dereference, Allocation of Resources Without Limits or Thrott
CISA ICS
ICONICS and Mitsubishi Electric Products
cisa_ics·2023-08-17·CVSS 7.5
[HIGH] ICONICS and Mitsubishi Electric Products
ICS Advisory
##
ICONICS and Mitsubishi Electric Products
Release DateAugust 17, 2023
Alert CodeICSA-23-229-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 5.9
- ATTENTION: Exploitable remotely
- Vendor: ICONICS, Mitsubishi Electric
- Equipment: ICONICS Product Suite
- Vulnerabilities: Buffer Overflow, Out-of-Bounds Read, Observable Timing Discrepancy, Double Free, and NULL Pointer Dereference
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could result in information disclosure, denial-of-service, or remote code execution.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
ICONICS reports these vulnerabilities affect the following products using OpenSSL:
-
ICONICS Suite including GENESIS64, Hyper Historian, AnalytiX, and MobileHMI:
Palo Alto
PAN-SA-2023-0001 Impact of OpenSSL Vulnerabilities Disclosed Feb 7, 2023
vendor_paloalto·2023-02-08·CVSS 4.9
CVE-2023-0286 [MEDIUM] PAN-SA-2023-0001 Impact of OpenSSL Vulnerabilities Disclosed Feb 7, 2023
PAN-SA-2023-0001 Impact of OpenSSL Vulnerabilities Disclosed Feb 7, 2023
The Palo Alto Networks Product Security Assurance team has evaluated the OpenSSL vulnerabilities that were disclosed on February 7, 2023 (CVE-2023-0286, CVE-2022-4304, CVE-2022-4203, CVE-2023-0215, CVE-2022-4450, CVE-2023-0216, CVE-2023-0217, and CVE-2023-0401) as it relates to our products. At this time, there are no demonstrated scenarios that enable successful
CVEs: CVE-2022-4203, CVE-2022-4304, CVE-2022-4450, CVE-2023-0215, CVE-2023-0216, CVE-2023-0217, CVE-2023-0286, CVE-2023-0401
Affected products: Cortex Data, Cortex XDR, Cortex XSOAR, Cortex Xpanse, GlobalProtect, PAN-OS, Prisma Access, Prisma Cloud, Prisma SD
Red Hat
openssl: read buffer overflow in X.509 certificate verification
vendor_redhat·2023-02-07·CVSS 4.9
CVE-2022-4203 [MEDIUM] CWE-125 openssl: read buffer overflow in X.509 certificate verification
openssl: read buffer overflow in X.509 certificate verification
A read buffer overrun can be triggered in X.509 certificate verification,
specifically in name constraint checking. Note that this occurs
after certificate chain signature verification and requires either a
CA to have signed the malicious certificate or for the application to
continue certificate verification despite failure to construct a path
to a trusted issuer.
The read buffer overrun might result in a crash which could lead to
a denial of service attack. In theory it could also result in the disclosure
of private memory contents (such as private keys, or sensitive plaintext)
although we are not aware of any working exploit leading to memory
contents disclosure as of the time of release of this advisory.
In a TLS client,
Ubuntu
OpenSSL vulnerabilities
vendor_ubuntu·2023-02-07·CVSS 4.9
CVE-2023-0217 [MEDIUM] OpenSSL vulnerabilities
Title: OpenSSL vulnerabilities
Summary: Several security issues were fixed in OpenSSL.
David Benjamin discovered that OpenSSL incorrectly handled X.400 address
processing. A remote attacker could possibly use this issue to read
arbitrary memory contents or cause OpenSSL to crash, resulting in a denial
of service. (CVE-2023-0286)
Corey Bonnell discovered that OpenSSL incorrectly handled X.509 certificate
verification. A remote attacker could possibly use this issue to cause
OpenSSL to crash, resulting in a denial of service. This issue only
affected Ubuntu 22.04 LTS and Ubuntu 22.10. (CVE-2022-4203)
Hubert Kario discovered that OpenSSL had a timing based side channel in the
OpenSSL RSA Decryption implementation. A remote attacker could possibly use
this issue to recover sensitive inform
Debian
CVE-2022-4203: openssl - A read buffer overrun can be triggered in X.509 certificate verification, specif...
vendor_debian·2022·CVSS 4.9
CVE-2022-4203 [MEDIUM] CVE-2022-4203: openssl - A read buffer overrun can be triggered in X.509 certificate verification, specif...
A read buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification and requires either a CA to have signed the malicious certificate or for the application to continue certificate verification despite failure to construct a path to a trusted issuer. The read buffer overrun might result in a crash which could lead to a denial of service attack. In theory it could also result in the disclosure of private memory contents (such as private keys, or sensitive plaintext) although we are not aware of any working exploit leading to memory contents disclosure as of the time of release of this advisory. In a TLS client, this can be triggered by connecting to a malicious server. In a T
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=c927a3492698c254637da836762f9b1f86cffabchttps://security.gentoo.org/glsa/202402-08https://www.openssl.org/news/secadv/20230207.txthttps://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=c927a3492698c254637da836762f9b1f86cffabchttps://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0003https://security.gentoo.org/glsa/202402-08https://www.openssl.org/news/secadv/20230207.txt
2023-02-24
Published