PatchSiren

PatchSiren cyber security CVE debrief

CVE-2022-4304 OpenSSL CVE debrief

CVE-2022-4304 is a timing-based RSA decryption side channel. In the advisory corpus, CISA maps the issue to Hitachi Energy Relion 670/650/SAM600-IO series and states that an attacker who can send many trial decryptions may be able to recover plaintext, potentially enough to decrypt data from an observed TLS connection.

Vendor
OpenSSL
Product
SINEC NMS
CVSS
MEDIUM 5.9
CISA KEV
Not listed in stored evidence
Original CVE published
2025-02-11
Original CVE updated
2025-05-06
Advisory published
2025-02-11
Advisory updated
2025-05-06

Who should care

OT/ICS operators using Hitachi Energy Relion 670/650/SAM600-IO devices, asset owners responsible for firmware/version management, and security teams protecting RSA/TLS-exposed industrial environments should treat this as relevant. It also matters to any team validating whether a deployed device falls inside the affected version ranges.

Technical summary

The underlying flaw is described as a timing-based side channel in OpenSSL RSA decryption. The advisory says the attack can support a Bleichenbacher-style recovery of plaintext after a very large number of trial messages. The stated impact is confidentiality: a successful attacker could recover a pre-master secret from an observed connection and then decrypt application data from that session. The advisory calls out all RSA padding modes named in the description, and the CVSS vector is AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N.

Defensive priority

Medium, with higher urgency for any exposed or externally reachable RSA/TLS use in the affected product families.

Recommended defensive actions

  • Validate whether any deployed devices match the affected product families and version ranges listed in the advisory.
  • Update Relion 670/650/SAM600-IO deployments to the vendor-fixed versions: 2.2.1.9 or later, 2.2.2.6 or later, 2.2.3.7 or later, 2.2.4.4 or later, or 2.2.5.6 or later, as applicable.
  • For Relion 670/650 series version 2.2.0 all revisions, apply the advisory's General Mitigation Factors.
  • Follow CISA ICS recommended practices and defense-in-depth guidance while planning and validating remediation.
  • Prioritize remediation on systems where RSA-based services are exposed to broader network access or where session confidentiality is especially sensitive.
  • Track the advisory update history, since CISA republished and updated the guidance after the initial 2023-06-27 disclosure.

Evidence notes

The supplied CISA CSAF advisory and the CVE description both identify a timing-based side channel in OpenSSL RSA decryption that can be used in a Bleichenbacher-style attack after many trial messages. The machine-readable advisory maps the issue to Hitachi Energy Relion 670/650/SAM600-IO series and provides affected version ranges plus fixed versions. The record was initially published on 2023-06-27 and the latest supplied update is 2026-03-17; those dates describe advisory handling, not the original vulnerability discovery date.

Sources and references

Verified primary and authoritative sources

  • CVE-2022-4304 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2022-4304

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2022-4304 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2022-4304

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-046-15.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-943925.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-943925.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/pdf/ssa-943925.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/txt/ssa-943925.txt

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-046-15

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.