Man-in-the-Middle (MitM) attack in OpenSSL - CVE-2022-1434

 

Man-in-the-Middle (MitM) attack in OpenSSL - CVE-2022-1434

Published: May 3, 2022 / Updated: February 22, 2023


Vulnerability identifier: #VU62767
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-1434
CWE-ID: CWE-300
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform MitM attack.

The vulnerability exists in OpenSSL 3.0 implementation of the RC4-MD5 ciphersuite due to incorrect usage of AAD data as the MAC key. This makes the MAC key trivially predictable. An attacker can perform a man-in-the-middle (MitM) attack to modify data being sent from one endpoint to an OpenSSL 3.0 recipient such that the modified data would still pass the MAC integrity check.


Affected software

OpenSSL
Amazon Linux AMI
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
openSUSE Leap
Ubuntu
cflinuxfs3
Brownfield Connectivity - Client
Platform Automation Toolkit
IBM Tivoli Netcool System Service Monitors/Application Service Monitors
IBM Integration Bus
IBM QRadar WinCollect Agent
Isolation Segment
VMware Tanzu Application Service for VMs
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Engineering Workflow Management
Steel Belted Radius Carrier Edition
IBM App Connect Enterprise
Engineering Lifecycle Management
libssl1.0.0 (Ubuntu package)
libssl1.1 (Ubuntu package)
openssl-3-debuginfo
openssl-3-debugsource
openssl-3-doc
libopenssl-3-devel-32bit
libopenssl3-32bit
libopenssl3-32bit-debuginfo
openssl-3
libopenssl3-debuginfo
libopenssl3
libopenssl-3-devel
libssl3 (Ubuntu package)
openssl

How to mitigate CVE-2022-1434

Install updates from vendor's website.

OpenSSL - update to 3.0.3
cflinuxfs3 - update to 0.292.0
IBM QRadar WinCollect Agent - update to 10.0.2
IBM App Connect Enterprise - update to 12.0.5.0
libssl1.0.0 (Ubuntu package) - update to 1.0.2n-1ubuntu5.9
libssl1.1 (Ubuntu package) - addressed in versions 1.1.1l-1ubuntu1.3, 1.1.1f-1ubuntu2.13, 1.1.1-1ubuntu2.1~18.04.17
Isolation Segment - addressed in versions 2.7.45, 2.10.25, 2.11.14, 2.12.8
VMware Tanzu Application Service for VMs - addressed in versions 2.7.50, 2.10.32, 2.11.20, 2.12.13, 2.13.5
Brownfield Connectivity - Client - update to 2.15
openssl-3-debuginfo - update to 3.0.1-150400.4.7.1
openssl-3-debugsource - update to 3.0.1-150400.4.7.1
openssl-3-doc - update to 3.0.1-150400.4.7.1
libopenssl-3-devel-32bit - update to 3.0.1-150400.4.7.1
libopenssl3-32bit - update to 3.0.1-150400.4.7.1
libopenssl3-32bit-debuginfo - update to 3.0.1-150400.4.7.1
openssl-3 - update to 3.0.1-150400.4.7.1
libopenssl3-debuginfo - update to 3.0.1-150400.4.7.1
libopenssl3 - update to 3.0.1-150400.4.7.1
libopenssl-3-devel - update to 3.0.1-150400.4.7.1
libssl3 (Ubuntu package) - update to 3.0.2-0ubuntu1.1
openssl - update to 3.0.5-1
Platform Automation Toolkit - addressed in versions 4.4.29, 5.0.22
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.6.2
Engineering Lifecycle Management - addressed in versions 7.0.1 iFix022, 7.0.2 iFix023
Engineering Workflow Management - addressed in versions 7.0.1 iFix022, 7.0.2 iFix023
Steel Belted Radius Carrier Edition - update to 8.6.0R16

External References

Related Security Bulletins