{"$schema":"https://docs.oasis-open.org/csaf/csaf/v2.1/schema/csaf.json","document":{"category":"csaf_security_advisory","csaf_version":"2.1","title":"OpenSSL Certificate Processing DoS Vulnerability (CVE-2022-0778)","distribution":{"tlp":{"label":"CLEAR"}},"publisher":{"category":"vendor","name":"WatchGuard PSIRT","namespace":"https://www.watchguard.com"},"tracking":{"id":"WGSA-2022-00011","status":"final","version":"41","initial_release_date":"2022-04-14T10:00:00+00:00","current_release_date":"2026-07-27T23:18:53.362867+00:00","revision_history":[{"date":"2022-04-14T10:00:00+00:00","number":"41","summary":"Initial release."}]},"references":[{"summary":"vendor-advisory","url":"https://psirt.watchguard.com/WGSA-2022-00011"},{"summary":"cve","url":"https://www.cve.org/CVERecord?id=CVE-2022-0778"}],"notes":[{"category":"summary","text":"On 15 March 2022, OpenSSL disclosed CVE-2022-0778, a bug in the BN_mod_sqrt() function responsible for calculating a modular square root, that could cause it to loop forever by crafting a certificate with invalid elliptic curve parameters. An attacker could exploit this vulnerability to trigger a Denial of Service attack against a vulnerable process.","title":"Summary"}]},"product_tree":{"branches":[{"category":"vendor","name":"WatchGuard","branches":[{"category":"product_name","name":"Fireware OS (Default)","branches":[{"category":"product_version_range","name":"vers >= 12.0, < 12.8-b659436","product":{"name":"Fireware OS (Default) vers >= 12.0, < 12.8-b659436","product_id":"CSAFPID-46ae0b14-8bdb-41f9-a57b-563a6e76c5c7-default"}}]},{"category":"product_name","name":"Fireware OS (FIPS)","branches":[{"category":"product_version_range","name":"vers >= 12.3.0, < 12.3.1_U2","product":{"name":"Fireware OS (FIPS) vers >= 12.3.0, < 12.3.1_U2","product_id":"CSAFPID-46ae0b14-8bdb-41f9-a57b-563a6e76c5c7-fips"}}]},{"category":"product_name","name":"Fireware OS (T15/T35)","branches":[{"category":"product_version_range","name":"vers >= 12.5, < 12.5.9-b655824","product":{"name":"Fireware OS (T15/T35) vers >= 12.5, < 12.5.9-b655824","product_id":"CSAFPID-46ae0b14-8bdb-41f9-a57b-563a6e76c5c7-t15/t35"}}]},{"category":"product_name","name":"WatchGuard System Manager","branches":[{"category":"product_version_range","name":"vers >= 12.0, < 12.8-b656510","product":{"name":"WatchGuard System Manager vers >= 12.0, < 12.8-b656510","product_id":"CSAFPID-534a58b7-3ceb-4eb8-9d1d-37d8a8028c45"}}]},{"category":"product_name","name":"Secure Wi-Fi","branches":[{"category":"product_version_range","name":"all versions","product":{"name":"Secure Wi-Fi all versions","product_id":"CSAFPID-6737224d-68ea-4d9e-80e7-1f38f4c398d8"}}]},{"category":"product_name","name":"Dimension","branches":[{"category":"product_version_range","name":"all versions","product":{"name":"Dimension all versions","product_id":"CSAFPID-d36d565e-228e-4d9a-888a-9be70889d829"}}]}]}]},"vulnerabilities":[{"notes":[{"category":"description","text":"On 15 March 2022, OpenSSL disclosed CVE-2022-0778, a bug in the BN_mod_sqrt() function responsible for calculating a modular square root, that could cause it to loop forever by crafting a certificate with invalid elliptic curve parameters. An attacker could exploit this vulnerability to trigger a Denial of Service attack against a vulnerable process.","title":"Summary"}],"product_status":{"known_affected":["CSAFPID-46ae0b14-8bdb-41f9-a57b-563a6e76c5c7-default","CSAFPID-46ae0b14-8bdb-41f9-a57b-563a6e76c5c7-fips","CSAFPID-46ae0b14-8bdb-41f9-a57b-563a6e76c5c7-t15/t35","CSAFPID-534a58b7-3ceb-4eb8-9d1d-37d8a8028c45"],"known_not_affected":["CSAFPID-6737224d-68ea-4d9e-80e7-1f38f4c398d8","CSAFPID-d36d565e-228e-4d9a-888a-9be70889d829"]},"cve":"CVE-2022-0778","remediations":[{"category":"vendor_fix","details":"Upgrade to Fireware OS 12.8-b659436 or later.","product_ids":["CSAFPID-46ae0b14-8bdb-41f9-a57b-563a6e76c5c7-default"]},{"category":"vendor_fix","details":"Upgrade to Fireware OS 12.5.9-b655824 or later.","product_ids":["CSAFPID-46ae0b14-8bdb-41f9-a57b-563a6e76c5c7-t15/t35"]},{"category":"vendor_fix","details":"Upgrade to Fireware OS 12.3.1_U2 or later.","product_ids":["CSAFPID-46ae0b14-8bdb-41f9-a57b-563a6e76c5c7-fips"]},{"category":"vendor_fix","details":"Upgrade to WatchGuard System Manager 12.8-b656510 or later.","product_ids":["CSAFPID-534a58b7-3ceb-4eb8-9d1d-37d8a8028c45"]}]}]}