CVE-2022-2097 Details
Description
AES OCB mode for 32-bit x86 platforms using the AES-NI assembly optimised implementation will not encrypt the entirety of the data under some circumstances. This could reveal sixteen bytes of data that was preexisting in the memory that wasn't written. In the special case of "in place" encryption, sixteen bytes of the plaintext would be revealed. Since OpenSSL does not support OCB based cipher suites for TLS and DTLS, they are both unaffected. Fixed in OpenSSL 3.0.5 (Affected 3.0.0-3.0.4). Fixed in OpenSSL 1.1.1q (Affected 1.1.1-1.1.1p).
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 26, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-327 | Use of a Broken or Risky Cryptographic Algorithm | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| openssl openssl | >= 1.1.1, < 1.1.1q >= 3.0.0, < 3.0.5 |
CPE
Remediation
| |
| fedoraproject fedora | 35 36 |
CPE
Remediation
| |
| netapp active iq unified manager | All versions |
CPE
Remediation
| |
| netapp clustered data ontap antivirus connector | All versions |
CPE
Remediation
| |
| netapp h300s firmware | All versions |
CPE
Remediation
| |
| netapp h500s firmware | All versions |
CPE
Remediation
| |
| netapp h500s | All versions |
CPE
Remediation
| |
| netapp h700s firmware | All versions |
CPE
Remediation
| |
| netapp h700s | All versions |
CPE
Remediation
| |
| netapp h410s firmware | All versions |
CPE
Remediation
| |
| netapp h410s | All versions |
CPE
Remediation
| |
| netapp h410c firmware | All versions |
CPE
Remediation
| |
| netapp h410c | All versions |
CPE
Remediation
| |
| siemens sinec ins | < 1.0 1.0 - 1.0 sp1 1.0 sp2 |
CPE
Remediation
| |
| debian debian linux | 10.0 11.0 |
CPE
Remediation
| |
Change History
20 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| Jun 21, 2024 | CVE Modified | [email protected] |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 7, 2023 | CVE Modified | [email protected] |
| Aug 8, 2023 | CWE Remap | [email protected] |
| Apr 20, 2023 | CVE Modified | [email protected] |
| Feb 23, 2023 | Modified Analysis | [email protected] |
| Feb 20, 2023 | CVE Modified | [email protected] |
| Feb 9, 2023 | CVE Modified | [email protected] |
| Jan 10, 2023 | CVE Modified | [email protected] |
| Oct 28, 2022 | Modified Analysis | [email protected] |
| Oct 16, 2022 | CVE Modified | [email protected] |
| Aug 26, 2022 | Modified Analysis | [email protected] |
| Jul 23, 2022 | CVE Modified | [email protected] |
| Jul 15, 2022 | CVE Modified | [email protected] |
| Jul 15, 2022 | CVE Modified | [email protected] |
| Jul 14, 2022 | Initial Analysis | [email protected] |
| Jul 9, 2022 | CVE Modified | [email protected] |