CVE Feed

    Dashboard / CVE / CVE-2022-1473

    CVE-2022-1473

    The OPENSSL_LH_flush() function, which empties a hash table, contains a bug that breaks reuse of the memory occuppied by the removed hash table entries. This function is used when decoding certificates or keys. If a long lived process periodically decodes certificates or keys its memory usage will expand without bounds and the process might be terminated by the operating system causing a denial of service. Also traversing the empty hash table entries will take increasingly more time. Typically such long lived processes might be TLS clients or TLS servers configured to accept client certificate authentication. The function was added in the OpenSSL 3.0 version thus older releases are not affected by the issue. Fixed in OpenSSL 3.0.3 (Affected 3.0.0,3.0.1,3.0.2).

    Published:May 3, 2022
    Last Modified:May 5, 2025
    EPS:May 3, 2022
    EPSS Score:0.00267
    CVSS Score:7.5

    Affected Products

    Vendor
    Netapp
    Product
    A250
    Vendor
    Netapp
    Product
    A250 Firmware
    Vendor
    Netapp
    Product
    A700s
    Vendor
    Netapp
    Product
    A700s Firmware
    Vendor
    Netapp
    Product
    Active Iq Unified Manager
    Vendor
    Netapp
    Product
    Aff 500f
    Vendor
    Netapp
    Product
    Aff 500f Firmware
    Vendor
    Netapp
    Product
    Aff 8300
    Vendor
    Netapp
    Product
    Aff 8300 Firmware
    Vendor
    Netapp
    Product
    Aff 8700
    Vendor
    Netapp
    Product
    Aff 8700 Firmware
    Vendor
    Netapp
    Product
    Aff A400
    Vendor
    Netapp
    Product
    Aff A400 Firmware
    Vendor
    Netapp
    Product
    Clustered Data Ontap
    Vendor
    Netapp
    Product
    Clustered Data Ontap Antivirus Connector
    Vendor
    Netapp
    Product
    Fabric-attached Storage A400
    Vendor
    Netapp
    Product
    Fabric-attached Storage A400 Firmware
    Vendor
    Netapp
    Product
    Fas 500f
    Vendor
    Netapp
    Product
    Fas 500f Firmware
    Vendor
    Netapp
    Product
    Fas 8300
    Vendor
    Netapp
    Product
    Fas 8300 Firmware
    Vendor
    Netapp
    Product
    Fas 8700
    Vendor
    Netapp
    Product
    Fas 8700 Firmware
    Vendor
    Netapp
    Product
    H300e
    Vendor
    Netapp
    Product
    H300e Firmware
    Vendor
    Netapp
    Product
    H300s
    Vendor
    Netapp
    Product
    H300s Firmware
    Vendor
    Netapp
    Product
    H410s
    Vendor
    Netapp
    Product
    H410s Firmware
    Vendor
    Netapp
    Product
    H500e
    Vendor
    Netapp
    Product
    H500e Firmware
    Vendor
    Netapp
    Product
    H500s
    Vendor
    Netapp
    Product
    H500s Firmware
    Vendor
    Netapp
    Product
    H700e
    Vendor
    Netapp
    Product
    H700e Firmware
    Vendor
    Netapp
    Product
    H700s
    Vendor
    Netapp
    Product
    H700s Firmware
    Vendor
    Netapp
    Product
    Santricity Smi-s Provider
    Vendor
    Netapp
    Product
    Smi-s Provider
    Vendor
    Netapp
    Product
    Snapmanager
    Vendor
    Netapp
    Product
    Solidfire\, Enterprise Sds \& Hci Storage Node
    Vendor
    Netapp
    Product
    Solidfire \& Hci Management Node
    Vendor
    Openssl
    Product
    Openssl
    Vendor
    Redhat
    Product
    Enterprise Linux

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High