VDB
CVE-2022-46393
CVE-2022-46393
PUBLISHED
CVSS 7.5 HIGH
An invalid pointer dereference on read can be triggered when an application tries to load malformed PKCS7 data with the d2i_PKCS7(), d2i_PKCS7_bio() or d2i_PKCS7_fp() functions. The result of the dereference is an application crash which could lead to a denial of service attack. The TLS implementation in OpenSSL does not call this function however third party applications might call these functions on untrusted data.
EPSS 0.93% · 76.4th percentile
Risk Scores
CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.93%
76.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| OpenSSL | OpenSSL | 3.0.0 |
Timeline
- Jun 28, 2021 PoC Published
- Dec 11, 2021 PoC Published
- Dec 13, 2021 PoC Published
- Dec 18, 2021 PoC Published
- Apr 7, 2022 PoC Published
- Jun 7, 2022 PoC Published
- Sep 16, 2022 PoC Published
- Dec 15, 2022 CVE Published
- Dec 16, 2022 EPSS Score
- Jan 27, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 9, 2023 EPSS Score
References
- https://cert-portal.siemens.com/productcert/html/ssa-716164.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-000072.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-602936.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-647068.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-943925.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-753746.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-806742.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-580228.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-797296.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-108696.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-871717.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-516818.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-017796.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-543502.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-665034.html advisory
- OpenSSL Advisory vendor-advisory
- 3.0.8 git commit patch
- https://security.gentoo.org/glsa/202402-08 url
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0003 url