The OpenSSL 3.0.4 release introduced a serious bug in the RSA implementation for X86_64 CPUs supporting the AVX512IFMA instructions. This issue makes the RSA implementation with 2048 bit private keys incorrect on such machines and memory corruption will happen during the computation. As a consequence of the memory corruption an attacker may be able to trigger a remote code execution on the machine performing the computation. SSL/TLS servers or other servers using 2048 bit RSA private keys running on machines supporting AVX512IFMA instructions of the X86_64 architecture are affected by this issue.
We have discovered 373,969 live websites that are affected by CVE-2022-2274.
| Product | |
| Category | Web Server Extensions |
| Vulnerable Domains | 373,969 live websites (76% of OpenSSL install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 18 versions ( 25% of all versions) |
| 97,884 websites | |
| 36,401 websites | |
| 23,171 websites | |
| 18,439 websites | |
| 14,291 websites | |
| 14,156 websites | |
| 13,185 websites | |
| 12,828 websites | |
| 12,170 websites | |
| .com | 143,244 websites |
| .org | 17,269 websites |
| .net | 17,140 websites |
| .nl | 13,944 websites |
| .de | 13,180 websites |
| .cz | 11,628 websites |
| .ru | 11,172 websites |
| .jp | 10,675 websites |
| .it | 7,947 websites |
| .edu | 5,429 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****.cz | *,*** | ||
| ****.com | *,*** | ||
| ********.com | *,*** | ||
| *.******.***.***.br | *,*** | ||
| *.*****.***.***.br | *,*** | ||
| ******.********.***.uk | *,*** | ||
| **.***.edu | *,*** | ||
| ***********************.com | *,*** | ||
| ****.**.com | *,*** | ||
| ***.***.edu | *,*** |