CVSS3
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
Percentile
55.2%
A security vulnerability has been discovered in OpenSSL. Fix for all versions is available.
CVEID:CVE-2022-4304
**DESCRIPTION:**OpenSSL could allow a remote attacker to obtain sensitive information, caused by a timing-based side channel in the RSA Decryption implementation. By sending an overly large number of trial messages for decryption, an attacker could exploit this vulnerability to obtain sensitive information.
CVSS Base score: 5.9
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/246612 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)
Affected Product(s) | Version(s) |
---|---|
IBM Elastic Storage System | 6.1.0.0 - 6.1.2.6 |
IBM Elastic Storage System | 6.1.3.0 - 6.1.8.0 |
IBM recommends that you fix this vulnerability by upgrading the affected versions of IBM Elastic Storage System 3000, 3200, 3500 and 5000 to the following code levels or higher:
V6.1.8.2 or later
V6.1.2.7 or later
None
Vendor | Product | Version | CPE |
---|---|---|---|
ibm | elastic_storage_system | 6.1. | cpe:2.3:a:ibm:elastic_storage_system:6.1.:*:*:*:*:*:*:* |
CVSS3
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
Percentile
55.2%