First published: Tue May 03 2022(Updated: )
Last updated 24 July 2024
Credit: openssl-security@openssl.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenSSL libcrypto | >=3.0.0<3.0.3 | |
netapp active iq unified manager vsphere | ||
NetApp Clustered Data ONTAP | ||
netapp clustered data ontap antivirus connector | ||
netapp santricity smi-s provider | ||
netapp smi-s provider | ||
netapp snapmanager hyper-v | ||
netapp solidfire\, enterprise sds \& hci storage node | ||
netapp solidfire \& hci management node | ||
All of | ||
NetApp AFF A700s Firmware | ||
netapp a700s | ||
All of | ||
netapp h300s firmware | ||
netapp h300s | ||
All of | ||
NetApp H500S Firmware | ||
netapp h500s | ||
All of | ||
netapp h700s firmware | ||
netapp h700s | ||
All of | ||
netapp h300e firmware | ||
netapp h300e | ||
All of | ||
netapp h500e firmware | ||
netapp h500e | ||
All of | ||
netapp h700e firmware | ||
netapp h700e | ||
All of | ||
netapp h410s firmware | ||
netapp h410s | ||
All of | ||
NetApp AFF 8300 Firmware | ||
NetApp AFF 8300 | ||
All of | ||
NetApp FAS8300 | ||
NetApp FAS8300 | ||
All of | ||
NetApp AFF 8700 | ||
NetApp AFF 8700 | ||
All of | ||
NetApp FAS8700 Firmware | ||
NetApp FAS8700 | ||
All of | ||
NetApp AFF A400 | ||
NetApp AFF A400 | ||
All of | ||
netapp fabric-attached storage a400 firmware | ||
netapp fabric-attached storage a400 | ||
All of | ||
netapp a250 firmware | ||
netapp a250 | ||
All of | ||
netapp aff 500f firmware | ||
netapp aff 500f | ||
All of | ||
netapp fas 500f firmware | ||
netapp fas 500f | ||
NetApp AFF A700s Firmware | ||
netapp a700s | ||
netapp h300s firmware | ||
netapp h300s | ||
NetApp H500S Firmware | ||
netapp h500s | ||
netapp h700s firmware | ||
netapp h700s | ||
netapp h300e firmware | ||
netapp h300e | ||
netapp h500e firmware | ||
netapp h500e | ||
netapp h700e firmware | ||
netapp h700e | ||
netapp h410s firmware | ||
netapp h410s | ||
NetApp AFF 8300 Firmware | ||
NetApp AFF 8300 | ||
NetApp FAS8300 | ||
NetApp FAS8300 | ||
NetApp AFF 8700 | ||
NetApp AFF 8700 | ||
NetApp FAS8700 Firmware | ||
NetApp FAS8700 | ||
NetApp AFF A400 | ||
NetApp AFF A400 | ||
netapp fabric-attached storage a400 firmware | ||
netapp fabric-attached storage a400 | ||
netapp a250 firmware | ||
netapp a250 | ||
netapp aff 500f firmware | ||
netapp aff 500f | ||
netapp fas 500f firmware | ||
netapp fas 500f | ||
debian/openssl | 1.1.1w-0+deb11u1 1.1.1w-0+deb11u2 3.0.15-1~deb12u1 3.0.14-1~deb12u2 3.4.0-2 3.4.1-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-1434 is a vulnerability in the OpenSSL 3.0 implementation of the RC4-MD5 ciphersuite.
CVE-2022-1434 affects OpenSSL 3.0 by incorrectly using the AAD data as the MAC key, making the MAC key predictable.
An attacker can exploit CVE-2022-1434 by performing a man-in-the-middle attack to modify data being sent to an OpenSSL 3.0 recipient.
CVE-2022-1434 has a severity rating of medium with a CVSS score of 5.9.
More information about CVE-2022-1434 can be found in the references provided: [Link 1](https://cert-portal.siemens.com/productcert/pdf/ssa-953464.pdf), [Link 2](https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=7d56a74a96828985db7354a55227a511615f732b), [Link 3](https://security.netapp.com/advisory/ntap-20220602-0009/).