OpenSSL vulnerabilities: Everything you need to know
ID: 768f7e60-66d5-5bf8-8868-5e836641fd42
STIX ID: report--768f7e60-66d5-5bf8-8868-5e836641fd42
Feed Name: Wiz Blog
**TL;DR:** OpenSSL disclosed two High-severity vulnerabilities (CVE-2022-3602 and CVE-2022-3786) in the X.509/punycode handling of OpenSSL 3.x that can cause buffer overflows and potentially remote code execution; exploitation is constrained (servers must use mTLS or clients must connect to attacker-controlled servers), available public POCs primarily cause crashes, only ~1.5% of OpenSSL instances are impacted in the analyzed cloud environments, and the vendor recommends upgrading to OpenSSL 3.0.7 while prioritizing internet-facing and mission-critical assets for patching.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
