CVE-2022-3602 and CVE-2022-3786
ID: 4dd2cf56-d72e-58de-98fc-60034dd59d2f
STIX ID: report--4dd2cf56-d72e-58de-98fc-60034dd59d2f
Feed Name: Arctic Wolf Blog
OpenSSL disclosed critical-sounding vulnerabilities (CVE-2022-3602 and CVE-2022-3786) affecting OpenSSL 3.0.0+; after further analysis the severity was downgraded to high. Arctic Wolf Labs reports that remote code execution is theoretically possible only in constrained scenarios requiring a certificate authority to sign a malicious certificate, and no active exploitation has been observed; organizations are advised to patch affected applications as part of normal patch cycles rather than out-of-band.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
