CVE-2022-1292

Advisory lineage Upstream: 0 Downstream: 34
Modified
Published: 03 May 2022, 15:15
Last modified:30 Dec 2025, 04:55

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
10 HIGH
v2.0 (nvd)
EPSS Score
38.89% HIGH
39% probability -2.32%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

03 May 2022, 15:15
Published
Vulnerability first disclosed
30 Dec 2025, 04:55
Last Modified
Vulnerability information updated

Description

The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the c_rehash script is considered obsolete and should be replaced by the OpenSSL rehash command line tool. Fixed in OpenSSL 3.0.3 (Affected 3.0.0,3.0.1,3.0.2). Fixed in OpenSSL 1.1.1o (Affected 1.1.1-1.1.1n). Fixed in OpenSSL 1.0.2ze (Affected 1.0.2-1.0.2zd).

CVSS Metrics

  • v3.1CRITICALScore: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • v3.1HIGHScore: 7.3CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
  • v2.0HIGHScore: 10AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS Trends

Current EPSS score: 38.89% Percentile: 97%

Techniques & Countermeasures

  • CWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

    The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Affected Systems

  • debiandebian_linux

    9.0 | 10.0 | 11.0

  • fedoraprojectfedora

    35 | 36

  • netappa250_firmware

    na

  • netappa700s_firmware

    na

  • netappactive_iq_unified_manager

    na

  • netappaff_500f_firmware

    na

  • netappaff_8300_firmware

    na

  • netappaff_8700_firmware

    na

  • netappaff_a400_firmware

    na

  • netappclustered_data_ontap

    na

  • netappclustered_data_ontap_antivirus_connector

    na

  • netappfabric-attached_storage_a400_firmware

    na

  • netappfas_500f_firmware

    na

  • netappfas_8300_firmware

    na

  • netappfas_8700_firmware

    na

  • netapph300e

    na

  • netapph300s_firmware

    na

  • netapph410s_firmware

    na

  • netapph500e

    na

  • netapph500s_firmware

    na

  • netapph700e

    na

  • netapph700s_firmware

    na

  • netapponcommand_insight

    na

  • netapponcommand_workflow_automation

    na

  • netappsantricity_smi-s_provider

    na

  • netappsmi-s_provider

    na

  • netappsnapcenter

    na

  • netappsnapmanager

    na

  • netappsolidfire_\&_hci_management_node

    na

  • netappsolidfire\,_enterprise_sds_\&_hci_storage_node

    na

  • UnknownOpenSSL

    Fixed in OpenSSL 3.0.3 (Affected 3.0.0,3.0.1,3.0.2) | Fixed in OpenSSL 1.1.1o (Affected 1.1.1-1.1.1n) | Fixed in OpenSSL 1.0.2ze (Affected 1.0.2-1.0.2zd) | ≥ 1.0.2, < 1.0.2ze | ≥ 1.1.1, < 1.1.1o | ≥ 3.0.0, < 3.0.3

  • oracleenterprise_manager_ops_center

    12.4.0.0

  • oraclemysql_server

    ≥ 5.0.0, ≤ 5.7.38 | ≥ 8.0.0, ≤ 8.0.29

  • oraclemysql_workbench

    ≤ 8.0.29

  • siemensbrownfield_connectivity_gateway

    < 2.15

References (15)