The OpenSSL 3.0.4 release introduced a serious bug in the RSA implementation for X86_64 CPUs supporting the AVX512IFMA instructions. This issue makes the RSA implementation with 2048 bit private keys incorrect on such machines and memory corruption will happen during the computation. As a consequence of the memory corruption an attacker may be able to trigger a remote code execution on the machine performing the computation. SSL/TLS servers or other servers using 2048 bit RSA private keys running on machines supporting AVX512IFMA instructions of the X86_64 architecture are affected by this issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HNetapp H300s
HWNetappall versionsNetapp H300s Firmware
OSNetappall versionsNetapp H410c
HWNetappall versionsNetapp H410c Firmware
OSNetappall versionsNetapp H410s
HWNetappall versionsNetapp H410s Firmware
OSNetappall versionsNetapp H500s
HWNetappall versionsNetapp H500s Firmware
OSNetappall versionsNetapp H700s
HWNetappall versionsNetapp H700s Firmware
OSNetappall versionsNetapp Snapcenter
APPNetappall versionsOpenSSL
APPOpenssl3.0.4
Related vulnerabilities
AMI MegaRAC SPx — zdalne ominięcie uwierzytelnienia w interfejsie Redfish BMC
Apache Log4j2 Log4Shell — RCE przez podatną funkcję JNDI lookup
OpenSSL CMS AuthEnvelopedData — niewystarczająca walidacja wejścia umożliwia atak oracle i bypass integralnośc...
OpenSSL: heap buffer overflow przy konwersji OCTET STRING na hex (32-bit)
NetApp SnapCenter — eskalacja uprawnień do administratora systemu zdalnego