Security Advisory – November, 2022: Neat Statement on the OpenSSL Critical Vulnerability
Advisory ID: NEAT-SA-2022-11-01
Publication date: November 1, 2022
Last updated: November 1, 2022
Severity: High — CVSS v3.1 Base Score: 7.5 for both CVE-2022-3602 and CVE-2022-3786
CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H (both CVEs, per NVD)
CVE ID: CVE-2022-3602 (remote code execution) and CVE-2022-3786 (denial of service)
Summary
The OpenSSL project released a security fix for two vulnerabilities affecting OpenSSL 3.0.0 through 3.0.6, patched in version 3.0.7. CVE-2022-3602 was initially described as enabling remote code execution and CVE-2022-3786 as enabling denial of service; both were later scored 7.5 (High) once further analysis showed exploitation was more difficult than first assessed.
Affected Products
None. Firmware running on Neat Bar, Neat Bar Pro, Neat Board, Neat Frame, and Neat Pad was not affected by CVE-2022-3602 or CVE-2022-3786.
Impact
Not applicable to Neat products. In general, remote code execution vulnerabilities can allow an attacker to execute malicious code on a target system, up to full control of the compromised machine; denial of service vulnerabilities can make a service or resource unavailable to its intended users.
Details
OpenSSL is an open-source cryptography library widely used to secure communications over SSL and TLS. These vulnerabilities affected OpenSSL versions 3.0.0 through 3.0.6.
Remediation
No action required for Neat products. Organizations running OpenSSL 3.0.0 through 3.0.6 directly should update to version 3.0.7 or later.
Acknowledgements
Not applicable.
References
- OpenSSL security advisory
- CVE-2022-3602 — National Vulnerability Database
- CVE-2022-3786 — National Vulnerability Database
Contact
Questions about this advisory can be directed to security@neat.no.