CVE Feed

    Dashboard / CVE / CVE-2022-1343

    CVE-2022-1343

    The function `OCSP_basic_verify` verifies the signer certificate on an OCSP response. In the case where the (non-default) flag OCSP_NOCHECKS is used then the response will be positive (meaning a successful verification) even in the case where the response signing certificate fails to verify. It is anticipated that most users of `OCSP_basic_verify` will not use the OCSP_NOCHECKS flag. In this case the `OCSP_basic_verify` function will return a negative value (indicating a fatal error) in the case of a certificate verification failure. The normal expected return value in this case would be 0. This issue also impacts the command line OpenSSL "ocsp" application. When verifying an ocsp response with the "-no_cert_checks" option the command line application will report that the verification is successful even though it has in fact failed. In this case the incorrect successful response will also be accompanied by error messages showing the failure and contradicting the apparently successful result. Fixed in OpenSSL 3.0.3 (Affected 3.0.0,3.0.1,3.0.2).

    Published:May 3, 2022
    Last Modified:May 5, 2025
    EPS:May 3, 2022
    EPSS Score:0.00127
    CVSS Score:5.3

    Affected Products

    Vendor
    Netapp
    Product
    A250
    Vendor
    Netapp
    Product
    A250 Firmware
    Vendor
    Netapp
    Product
    A700s
    Vendor
    Netapp
    Product
    A700s Firmware
    Vendor
    Netapp
    Product
    Active Iq Unified Manager
    Vendor
    Netapp
    Product
    Aff 500f
    Vendor
    Netapp
    Product
    Aff 500f Firmware
    Vendor
    Netapp
    Product
    Aff 8300
    Vendor
    Netapp
    Product
    Aff 8300 Firmware
    Vendor
    Netapp
    Product
    Aff 8700
    Vendor
    Netapp
    Product
    Aff 8700 Firmware
    Vendor
    Netapp
    Product
    Aff A400
    Vendor
    Netapp
    Product
    Aff A400 Firmware
    Vendor
    Netapp
    Product
    Clustered Data Ontap
    Vendor
    Netapp
    Product
    Clustered Data Ontap Antivirus Connector
    Vendor
    Netapp
    Product
    Fabric-attached Storage A400
    Vendor
    Netapp
    Product
    Fabric-attached Storage A400 Firmware
    Vendor
    Netapp
    Product
    Fas 500f
    Vendor
    Netapp
    Product
    Fas 500f Firmware
    Vendor
    Netapp
    Product
    Fas 8300
    Vendor
    Netapp
    Product
    Fas 8300 Firmware
    Vendor
    Netapp
    Product
    Fas 8700
    Vendor
    Netapp
    Product
    Fas 8700 Firmware
    Vendor
    Netapp
    Product
    H300e
    Vendor
    Netapp
    Product
    H300e Firmware
    Vendor
    Netapp
    Product
    H300s
    Vendor
    Netapp
    Product
    H300s Firmware
    Vendor
    Netapp
    Product
    H410s
    Vendor
    Netapp
    Product
    H410s Firmware
    Vendor
    Netapp
    Product
    H500e
    Vendor
    Netapp
    Product
    H500e Firmware
    Vendor
    Netapp
    Product
    H500s
    Vendor
    Netapp
    Product
    H500s Firmware
    Vendor
    Netapp
    Product
    H700e
    Vendor
    Netapp
    Product
    H700e Firmware
    Vendor
    Netapp
    Product
    H700s
    Vendor
    Netapp
    Product
    H700s Firmware
    Vendor
    Netapp
    Product
    Santricity Smi-s Provider
    Vendor
    Netapp
    Product
    Smi-s Provider
    Vendor
    Netapp
    Product
    Snapmanager
    Vendor
    Netapp
    Product
    Solidfire\, Enterprise Sds \& Hci Storage Node
    Vendor
    Netapp
    Product
    Solidfire \& Hci Management Node
    Vendor
    Openssl
    Product
    Openssl
    Vendor
    Redhat
    Product
    Enterprise Linux

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High