Security features bypass in OpenSSL - CVE-2022-1343
Published: May 3, 2022 / Updated: February 22, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform MitM attack.
The vulnerability exists due to an error when validating OCSP response within the OCSP_basic_verify function. In the case where the (non-default) flag OCSP_NOCHECKS is used then the
response will be positive (meaning a successful verification) even in
the case where the response signing certificate fails to verify. A remote attacker can perform MitM attack.
Affected software
Amazon Linux AMI
Fedora
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Desktop
openSUSE Leap
Ubuntu
SINAMICS PERFECT HARMONY GH180 6SR5
SINAMICS SL150
SINAMICS GL150
SCALANCE S615
cflinuxfs3
Brownfield Connectivity - Client
Platform Automation Toolkit
IBM Tivoli Netcool System Service Monitors/Application Service Monitors
IBM QRadar WinCollect Agent
IBM Integration Bus
Isolation Segment
VMware Tanzu Application Service for VMs
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Engineering Workflow Management
Steel Belted Radius Carrier Edition
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libssl1.0.0 (Ubuntu package)
libssl1.1 (Ubuntu package)
openssl3
openssl (Red Hat package)
libopenssl3-32bit-debuginfo
libopenssl3-32bit
libopenssl-3-devel
libopenssl-3-devel-32bit
libopenssl3
libopenssl3-debuginfo
openssl-3
openssl-3-debuginfo
openssl-3-debugsource
openssl-3-doc
libssl3 (Ubuntu package)
openssl
IBM App Connect Enterprise
Engineering Lifecycle Management
SCALANCE M826-2 SHDSL-Router
RUGGEDCOM RM1224 LTE(4G) EU
RUGGEDCOM RM1224 LTE(4G) NAM
SCALANCE M804PB
SCALANCE M812-1 ADSL-Router (Annex A)
SCALANCE M812-1 ADSL-Router (Annex B)
SCALANCE M816-1 ADSL-Router (Annex A)
SCALANCE S615 EEC
SCALANCE MUM856-1 (RoW)
SCALANCE MUM856-1 (EU)
SCALANCE MUM853-1 (EU)
SCALANCE M876-4 (NAM)
SCALANCE M876-4 (EU)
SCALANCE M876-4
SCALANCE M876-3 (ROK)
SCALANCE M876-3 (EVDO)
SCALANCE M874-3
SCALANCE M874-2
SCALANCE M816-1 ADSL-Router (Annex B)
How to mitigate CVE-2022-1343
cflinuxfs3 - update to 0.292.0
IBM QRadar WinCollect Agent - update to 10.0.2
IBM App Connect Enterprise - update to 12.0.5.0
libssl1.0.0 (Ubuntu package) - update to 1.0.2n-1ubuntu5.9
libssl1.1 (Ubuntu package) - addressed in versions 1.1.1l-1ubuntu1.3, 1.1.1f-1ubuntu2.13, 1.1.1-1ubuntu2.1~18.04.17
Isolation Segment - addressed in versions 2.7.45, 2.10.25, 2.11.14, 2.12.8
VMware Tanzu Application Service for VMs - addressed in versions 2.7.50, 2.10.32, 2.11.20, 2.12.13, 2.13.5
Brownfield Connectivity - Client - update to 2.15
openssl3 - update to 3.0.1-41.el8.1
openssl (Red Hat package) - update to 3.0.1-41.el9_0
libopenssl3-32bit-debuginfo - update to 3.0.1-150400.4.7.1
libopenssl3-32bit - update to 3.0.1-150400.4.7.1
libopenssl-3-devel - update to 3.0.1-150400.4.7.1
libopenssl-3-devel-32bit - update to 3.0.1-150400.4.7.1
libopenssl3 - update to 3.0.1-150400.4.7.1
libopenssl3-debuginfo - update to 3.0.1-150400.4.7.1
openssl-3 - update to 3.0.1-150400.4.7.1
openssl-3-debuginfo - update to 3.0.1-150400.4.7.1
openssl-3-debugsource - update to 3.0.1-150400.4.7.1
openssl-3-doc - update to 3.0.1-150400.4.7.1
libssl3 (Ubuntu package) - update to 3.0.2-0ubuntu1.1
openssl - update to 3.0.5-1
Platform Automation Toolkit - addressed in versions 4.4.29, 5.0.22
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.6.2
Engineering Workflow Management - addressed in versions 7.0.1 iFix022, 7.0.2 iFix023
Engineering Lifecycle Management - addressed in versions 7.0.1 iFix022, 7.0.2 iFix023
SCALANCE M826-2 SHDSL-Router - update to 7.2
SCALANCE S615 - update to 7.2
RUGGEDCOM RM1224 LTE(4G) EU - update to 7.2
RUGGEDCOM RM1224 LTE(4G) NAM - update to 7.2
SCALANCE M804PB - update to 7.2
SCALANCE M812-1 ADSL-Router (Annex A) - update to 7.2
SCALANCE M812-1 ADSL-Router (Annex B) - update to 7.2
SCALANCE M816-1 ADSL-Router (Annex A) - update to 7.2
SCALANCE S615 EEC - update to 7.2
SCALANCE MUM856-1 (RoW) - update to 7.2
SCALANCE MUM856-1 (EU) - update to 7.2
SCALANCE MUM853-1 (EU) - update to 7.2
SCALANCE M876-4 (NAM) - update to 7.2
SCALANCE M876-4 (EU) - update to 7.2
SCALANCE M876-4 - update to 7.2
SCALANCE M876-3 (ROK) - update to 7.2
SCALANCE M876-3 (EVDO) - update to 7.2
SCALANCE M874-3 - update to 7.2
SCALANCE M874-2 - update to 7.2
SCALANCE M816-1 ADSL-Router (Annex B) - update to 7.2
Steel Belted Radius Carrier Edition - update to 8.6.0R16
External References
Related Security Bulletins
- Multiple vulnerabilities in OpenSSL
- Ubuntu update for openssl
- Multiple vulnerabilities in Cloud Foundry Foundation cflinuxfs3
- Multiple vulnerabilities in IBM QRadar WinCollect Agent
- Multiple vulnerabilities in IBM App Connect Enterprise and IBM Integration Bus
- Multiple vulnerabilities in IBM Tivoli Netcool System Service Monitors/Application Service Monitors
- SUSE update for openssl-3
- Red Hat Enterprise Linux 9 update for openssl
- Multiple vulnerabilities in Juniper Networks Steel Belted Radius Carrier Edition
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilites in Siemens Brownfield Connectivity - Client
- Multiple vulnerabilities in Siemens RUGGEDCOM and SCALANCE Products
- VMware Tanzu products update for OpenSSL
- Multiple vulnerabilities in Siemens Integrated SCALANCE S615 of SINAMICS Medium Voltage products
- Multiple vulnerabilities in IBM Engineering Workflow Management (EWM)
- Amazon Linux AMI update for openssl
- Fedora EPEL 8 update for openssl3