OpenSSL Security Advisory by Luke Richards
ID: 46ee8afe-6771-557f-9d87-3f5790daf763
STIX ID: report--46ee8afe-6771-557f-9d87-3f5790daf763
Feed Name: Vectra AI Blog
Threat Score
OpenSSL released advisories for CVE-2022-3602 and CVE-2022-3768 — buffer overflow flaws in the X.509 email address field affecting OpenSSL 3.0.0–3.0.6. Exploitation requires user/client interaction or client certificate authentication and trusted CA-signed certificates, limiting practical risk; no active exploitation has been reported. Patching to OpenSSL 3.0.7 is recommended, and the report lists Vectra detections and post-compromise behaviors to monitor.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
