CVE-2022-26083: High severity intel cryptography for intel integrated performance primitives vulnerability
Published Feb 14, 2025
·Updated
Generation of weak initialization vector in an Intel(R) IPP Cryptography software library before version 2021.5 may allow an unauthenticated user to potentially enable information disclosure via local access.
Affected Software
2 affected components
Intel Ipp Cryptography<2021.5
Intel Integrated Performance Primitives Cryptography<2021.5
Event History
Feb 14, 2025
CVE Published
via MITRE·08:41 PM
Data Sourced
via MITRE·08:41 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-26083?
CVE-2022-26083 is classified as a medium severity vulnerability.
2
How do I fix CVE-2022-26083?
To fix CVE-2022-26083, update to Intel IPP Cryptography software version 2021.5 or later.
3
What is the impact of CVE-2022-26083?
CVE-2022-26083 may allow an unauthenticated user to potentially enable information disclosure.
4
Who is affected by CVE-2022-26083?
CVE-2022-26083 affects users of the Intel IPP Cryptography software library prior to version 2021.5.
5
What causes CVE-2022-26083?
CVE-2022-26083 is caused by the generation of weak initialization vectors in the affected software.