{"$schema":"https://docs.oasis-open.org/csaf/csaf/v2.1/schema/csaf.json","document":{"category":"csaf_informational_advisory","csaf_version":"2.1","title":"OpenSSL CVE-2022-3602 and CVE-2022-3786","distribution":{"tlp":{"label":"CLEAR"}},"publisher":{"category":"vendor","name":"WatchGuard PSIRT","namespace":"https://www.watchguard.com"},"tracking":{"id":"WGSA-2022-00021","status":"final","version":"25","initial_release_date":"2022-11-01T16:28:48+00:00","current_release_date":"2026-07-28T01:16:41.225439+00:00","revision_history":[{"date":"2022-11-01T16:28:48+00:00","number":"25","summary":"Initial release."}]},"references":[{"summary":"vendor-advisory","url":"https://psirt.watchguard.com/WGSA-2022-00021"},{"summary":"cve","url":"https://www.cve.org/CVERecord?id=CVE-2022-3602"},{"summary":"cve","url":"https://www.cve.org/CVERecord?id=CVE-2022-3786"}],"notes":[{"category":"summary","text":"On 1 November 2022, OpenSSL disclosed CVE-2022-3602 and CVE-2022-3786, two high severity buffer overflow vulnerabilities in certificate validation present in OpenSSL 3.0.x up to and including 3.0.6. An attacker could exploit either vulnerability with a maliciously-crafted certificate that has been signed by a trusted certificate authority.\n\nPre-announcements of CVE-2022-3602 described this issue as CRITICAL.\nFurther analysis based on some of the mitigating factors have led this to be downgraded to HIGH.\n\nNo WatchGuard products are affected by these vulnerabilities","title":"Summary"}]}}