CVE Feed

    Dashboard / CVE / CVE-2022-1292

    CVE-2022-1292

    The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the c_rehash script is considered obsolete and should be replaced by the OpenSSL rehash command line tool. Fixed in OpenSSL 3.0.3 (Affected 3.0.0,3.0.1,3.0.2). Fixed in OpenSSL 1.1.1o (Affected 1.1.1-1.1.1n). Fixed in OpenSSL 1.0.2ze (Affected 1.0.2-1.0.2zd).

    Published:May 3, 2022
    Last Modified:Dec 30, 2025
    EPS:May 3, 2022
    EPSS Score:0.41209
    CVSS Score:9.8

    Affected Products

    Vendor
    Debian
    Product
    Debian Linux
    Vendor
    Fedoraproject
    Product
    Fedora
    Vendor
    Netapp
    Product
    A250
    Vendor
    Netapp
    Product
    A250 Firmware
    Vendor
    Netapp
    Product
    A700s
    Vendor
    Netapp
    Product
    A700s Firmware
    Vendor
    Netapp
    Product
    Active Iq Unified Manager
    Vendor
    Netapp
    Product
    Aff 500f
    Vendor
    Netapp
    Product
    Aff 500f Firmware
    Vendor
    Netapp
    Product
    Aff 8300
    Vendor
    Netapp
    Product
    Aff 8300 Firmware
    Vendor
    Netapp
    Product
    Aff 8700
    Vendor
    Netapp
    Product
    Aff 8700 Firmware
    Vendor
    Netapp
    Product
    Aff A400
    Vendor
    Netapp
    Product
    Aff A400 Firmware
    Vendor
    Netapp
    Product
    Clustered Data Ontap
    Vendor
    Netapp
    Product
    Clustered Data Ontap Antivirus Connector
    Vendor
    Netapp
    Product
    Fabric-attached Storage A400
    Vendor
    Netapp
    Product
    Fabric-attached Storage A400 Firmware
    Vendor
    Netapp
    Product
    Fas 500f
    Vendor
    Netapp
    Product
    Fas 500f Firmware
    Vendor
    Netapp
    Product
    Fas 8300
    Vendor
    Netapp
    Product
    Fas 8300 Firmware
    Vendor
    Netapp
    Product
    Fas 8700
    Vendor
    Netapp
    Product
    Fas 8700 Firmware
    Vendor
    Netapp
    Product
    H300e
    Vendor
    Netapp
    Product
    H300e Firmware
    Vendor
    Netapp
    Product
    H300s
    Vendor
    Netapp
    Product
    H300s Firmware
    Vendor
    Netapp
    Product
    H410s
    Vendor
    Netapp
    Product
    H410s Firmware
    Vendor
    Netapp
    Product
    H500e
    Vendor
    Netapp
    Product
    H500e Firmware
    Vendor
    Netapp
    Product
    H500s
    Vendor
    Netapp
    Product
    H500s Firmware
    Vendor
    Netapp
    Product
    H700e
    Vendor
    Netapp
    Product
    H700e Firmware
    Vendor
    Netapp
    Product
    H700s
    Vendor
    Netapp
    Product
    H700s Firmware
    Vendor
    Netapp
    Product
    Oncommand Insight
    Vendor
    Netapp
    Product
    Oncommand Workflow Automation
    Vendor
    Netapp
    Product
    Santricity Smi-s Provider
    Vendor
    Netapp
    Product
    Smi-s Provider
    Vendor
    Netapp
    Product
    Snapcenter
    Vendor
    Netapp
    Product
    Snapmanager
    Vendor
    Netapp
    Product
    Solidfire\, Enterprise Sds \& Hci Storage Node
    Vendor
    Netapp
    Product
    Solidfire \& Hci Management Node
    Vendor
    Openssl
    Product
    Openssl
    Vendor
    Oracle
    Product
    Enterprise Manager Ops Center
    Vendor
    Oracle
    Product
    Mysql Server
    Vendor
    Oracle
    Product
    Mysql Workbench
    Vendor
    Redhat
    Product
    Enterprise Linux
    Vendor
    Redhat
    Product
    Jboss Core Services
    Vendor
    Redhat
    Product
    Jboss Enterprise Web Server
    Vendor
    Redhat
    Product
    Rhel Satellite Client
    Vendor
    Redhat
    Product
    Satellite
    Vendor
    Redhat
    Product
    Satellite Capsule
    Vendor
    Siemens
    Product
    Brownfield Connectivity Gateway

    Related CVEs

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High