← Back to Vulnerability Reports CVE Intelligence

CVE-2022-4304

Openssl (also: Stormshield)MEDIUM · CVSS 5.9No exploitation reported

What is CVE-2022-4304?

A timing based side channel exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a plaintext across a network in a Bleichenbacher style attack. To achieve a successful decryption an attacker would have to be able to send a very large number of trial messages for decryption. The vulnerability affects all RSA padding modes: PKCS#1 v1.5, RSA-OEAP and RSASVE. For example, in a TLS connection, RSA is commonly used by a client to send an encrypted pre-master secret to the server. An attacker that had observed a genuine connection between a client and a server could use this flaw to send trial messages to the server and record the time taken to process them. After a sufficiently large number of messages the attacker could recover the pre-master secret used for the original connection and thus be able to decrypt the application data sent over that connection.

CVSS5.9 NVD 3.1
SeverityMEDIUM
ExploitationNo exploitation reported
Triage statusNo Known Exploit
ActionSchedule for next cycle
CVSS vectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
NVD published2023-02-08
NVD last modified2025-11-04

Affected product

Openssl (also: Stormshield)

NVD also lists CPE entries for: Openssl, Stormshield Endpoint Security, Stormshield Sslvpn, Stormshield Network Security

Remediation Steps

  1. Contact Hitachi Energy for the latest GMS600 firmware that addresses the OpenSSL vulnerability
  2. Review the version of OpenSSL bundled in your GMS600 deployment against known vulnerable releases
  3. Plan a maintenance window for firmware update deployment
  4. Test the update in a non-production environment before deploying to operational systems

Coverage on defend.network

🤖 This CVE page is generated by defend.network from NVD, CISA KEV, EPSS, and our verified daily briefings. Severity and exploitation data come from official sources; always verify remediation steps against the official vendor advisory before acting in production.

Get Critical CVE Alerts

Subscribe free and hear about actively exploited CVEs like this one first.