CVE-2022-4304General(openssl / endpoint_security)

LOWCVSS 5.9 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A timing based side channel exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a plaintext across a network in a Bleichenbacher style attack. To achieve a successful decryption an attacker would have to be able to send a very large number of trial messages for decryption. The vulnerability affects all RSA padding modes: PKCS#1 v1.5, RSA-OEAP and RSASVE. For example, in a TLS connection, RSA is commonly used by a client to send an encrypted pre-master secret to the server. An attacker that had observed a genuine connection between a client and a server could use this flaw to send trial messages to the server and record the time taken to process them. After a sufficiently large number of messages the attacker could recover the pre-master secret used for the original connection and thus be able to decrypt the application data sent over that connection.

2.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-203

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • endpoint_security
  • openssl
  • sslvpn
  • stormshield_network_security

Threat summary

  • Public PoC is present in monitored signal
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-05-21); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
endpoint_securityopensslsslvpnstormshield_network_security

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-21: 1Mentions · 2026-06-30: 1PoC Mentioned / Linked · 2026-05-21: 1Technical Details · 2026-05-21: 1Technical Details · 2026-06-30: 105-2106-30
Signal classification2 categories
General
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-211
General1
2026-06-301
Disclosure1
Full discourse2 posts
  • BREACHSPIDER@breachspider
    Disclosure

    [CVE Analysis] CVE-2022-4304: OpenSSL Timing Oracle in Hitachi Energy GMS600 Exposes RSA Key Exchange to Decryption https://breachspider.com/intel/2026-06-30-cve-2022-4304-openssl-timing-oracle-in-hitachi-energy-gms600 #ICS #OTSecurity #SCADA #CriticalInfrastructure

    Post summary

    The post announces CVE-2022-4304, a timing‑oracle vulnerability in OpenSSL that could decrypt RSA key exchanges on Hitachi Energy GMS600, but it provides no exploit or patch information.

    0100055
    2.3K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    General

    TRC analysis shows CVE-2022-4304 enables timing-based attacks against Hitachi Energy's GMS600 through OpenSSL RSA decryption flaws. Attackers exploit TLS session vulnerabilities to decrypt sensitive data via Bleichenbacher-style side-channel techniques. #CloudSecurity 🔗 Full breakdown: https://aviatrix.ai/threat-research-center/hitachi-energy-gms600-openssl-vulnerability-cve-2022-4304

    Post summary

    The post analyzes CVE-2022-4304, detailing timing-based attacks against Hitachi Energy's GMS600 via OpenSSL RSA flaws, and provides a link to a full technical breakdown, but does not mention active exploitation or mitigation steps.

    0000038
    1.9K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appopensslopenssl---
Appstormshieldendpoint_security---
Appstormshieldsslvpn---
Appstormshieldstormshield_network_security---

Explore more