VDB
CVE-2022-27782
CVE-2022-27782
PUBLISHED
EPSS 0.47% · 64.9th percentile
Risk Scores
EPSS Score
0.47%
64.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Amazon | curl |
Exploit Intelligence
- CVE-2026-8932: incomplete mTLS config matching in conn reuse (hackerone)
- CVE-2026-8286: wrong STARTTLS connection reuse (hackerone)
- CVE-2026-8286: wrong STARTTLS connection reuse (hackerone)
- CVE-2026-8932: incomplete mTLS config matching in conn reuse (hackerone)
- SSH/SFTP connection reuse can bypass SSH key identity after ssh_config_matches removal (hackerone)
- SSH/SFTP connection reuse can bypass SSH key identity after ssh_config_matches removal (hackerone)
- https://www.cisa.gov/news-events/alerts/2023/05/01/cisa-adds-three-known-exploited-vulnerabilities-catalog (certbund)
- https://hackerone.com/reports/1555796 (nist-nvd)
- CVE-2008-5161 OpenSSH 4.7p1 Audit Helper Automates version checking and credential auditing of legacy OpenSSH 4.7p1 (Debian-8ubuntu1) targets by driving Metasploit’s auxiliary/scanner/ssh/ssh_login module from Python via pwntools. (github-poc)
- CVE-2008-5161 OpenSSH 4.7p1 Audit Helper Automates version checking and credential auditing of legacy OpenSSH 4.7p1 (Debian-8ubuntu1) targets by driving Metasploit’s auxiliary/scanner/ssh/ssh_login module from Python via pwntools. (github-poc)
…and 35 more exploits
Timeline
- CVE Published
- May 11, 2022 PoC Published
- May 12, 2022 PoC Published
- Jun 2, 2022 EPSS Score
- Jul 22, 2022 EPSS Score
- Sep 8, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 14, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 21, 2023 EPSS Score
- May 9, 2023 EPSS Score
- Jun 26, 2023 EPSS Score
References
- ALAS-2022-1646: curl (medium) advisory