← Vulnerability feed

Vulnerability record · CVE-2022-1292 · published 3 May 2022

CVE-2022-1292: OpenSSL c_rehash script command injection via unsanitised shell metacharacters

Siemens · Brownfield Connectivity Gateway

The c_rehash script shipped with OpenSSL fails to sanitise shell metacharacters, allowing command injection. On operating systems that execute the script automatically, an attacker can run arbitrary commands with the privileges of that script. The script is obsolete and should be replaced by the OpenSSL rehash command line tool.

7.3 CVSS 3.1 High EPSS 83% · top 0.3% CWE-78 · OS command injection
7.3CVSS 3.1 base score, v2 10.0
83%EPSS exploitation probability, 30 days
NoNot in CISA KEV
35Affected product versions listed by NVD
29References
17 Jun 2026Last modified by NVD

Description

The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the c_rehash script is considered obsolete and should be replaced by the OpenSSL rehash command line tool. Fixed in OpenSSL 3.0.3 (Affected 3.0.0,3.0.1,3.0.2). Fixed in OpenSSL 1.1.1o (Affected 1.1.1-1.1.1n). Fixed in OpenSSL 1.0.2ze (Affected 1.0.2-1.0.2zd).

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityHigh CVSS (7.3) command injection with very high EPSS, though exploitation requires local access and user interaction and it is not in KEV.

What it is

The c_rehash script shipped with OpenSSL fails to sanitise shell metacharacters, allowing command injection. On operating systems that execute the script automatically, an attacker can run arbitrary commands with the privileges of that script. The script is obsolete and should be replaced by the OpenSSL rehash command line tool.

Impact

An attacker gains arbitrary command execution at the privilege level of the c_rehash script, which on some systems is elevated or automated. This can lead to full compromise of the host or the OpenSSL-using service context.

Attack surface

Reached locally per the CVSS vector (AV:L) with low privileges required (PR:L) and user interaction needed (UI:R), typically by placing crafted files or paths that the script processes. No network vector is indicated.

Exploitation

Not listed in CISA KEV and no ransomware usage documented, but EPSS is very high at 0.826 (99.6th percentile), indicating substantial observed or expected exploitation activity. References are advisory and patch commits, with no public exploit tag supplied.

What to do

  • Patch OpenSSL to 3.0.3, 1.1.1o, or 1.0.2ze as applicable to the deployed branch.
  • Stop using the c_rehash script and switch to the OpenSSL rehash command line tool.
  • Remove or restrict execution of c_rehash on systems where it is invoked automatically.
  • Audit OS packages and third-party products that bundle OpenSSL for the affected script and update them.
  • Restrict local write access to directories processed by c_rehash to trusted users only.

Detection

  • Monitor process execution for c_rehash invocations, especially from automated or privileged contexts.
  • Alert on shell metacharacters (;, |, $(), backticks) appearing in arguments or filenames passed to c_rehash.
  • Hunt for unexpected child processes spawned by c_rehash or by services that call it.
  • Review file creation in certificate directories for names containing shell metacharacters.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

35 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://cert-portal.siemens.com/productcert/pdf/ssa-953464.pdf Third Party Advisory
https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=1ad73b4d27bd8c1b369a3cd453681d3a4f1bb9b2 Broken Link
https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=548d3f280a6e737673f5b61fce24bb100108dfeb Broken Link
https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=e5fd1728ef4c7a5bf7c7a7163ca60370460a6e23 Broken Link
https://lists.debian.org/debian-lts-announce/2022/05/msg00019.html Mailing ListThird Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VX4KWHPMKYJL6ZLW4M5IU7E Mailing ListThird Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZNU5M7BXMML26G3GPYKFGQY Mailing ListThird Party Advisory
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0011 Third Party Advisory
https://security.gentoo.org/glsa/202210-02 Third Party Advisory
https://security.netapp.com/advisory/ntap-20220602-0009/ Third Party Advisory
https://security.netapp.com/advisory/ntap-20220729-0004/ Third Party Advisory
https://www.debian.org/security/2022/dsa-5139 Third Party Advisory
https://www.openssl.org/news/secadv/20220503.txt Vendor Advisory
https://www.oracle.com/security-alerts/cpujul2022.html Third Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-953464.pdf Third Party Advisory
https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=1ad73b4d27bd8c1b369a3cd453681d3a4f1bb9b2 Broken Link
https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=548d3f280a6e737673f5b61fce24bb100108dfeb Broken Link
https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=e5fd1728ef4c7a5bf7c7a7163ca60370460a6e23 Broken Link
https://gitlab.com/fraf0/cve-2022-1292-re_score-analysis
https://lists.debian.org/debian-lts-announce/2022/05/msg00019.html Mailing ListThird Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VX4KWHPMKYJL6ZLW4M5IU7E Mailing ListThird Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZNU5M7BXMML26G3GPYKFGQY Mailing ListThird Party Advisory
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0011 Third Party Advisory
https://security.gentoo.org/glsa/202210-02 Third Party Advisory
https://security.netapp.com/advisory/ntap-20220602-0009/ Third Party Advisory
https://security.netapp.com/advisory/ntap-20220729-0004/ Third Party Advisory
https://www.debian.org/security/2022/dsa-5139 Third Party Advisory
https://www.openssl.org/news/secadv/20220503.txt Vendor Advisory
https://www.oracle.com/security-alerts/cpujul2022.html Third Party Advisory

Track CVE-2022-1292 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-32433Erlang/OTP SSH server missing authentication allows remote code executionErlang/OTP SSH servers before OTP-27.3.3, OTP-26.2.5.11 and OTP-25.3.2.20 mishandle SSH protocol messages, letting an unauthenticated attacker execut…KEVEPSS 99%analysed10.0CVE-2025-24201Apple WebKit out-of-bounds write allows sandbox escapeCVE-2025-24201 is an out-of-bounds write in Apple's WebKit that was addressed with improved checks. Maliciously crafted web content may break out of …KEVEPSS 3.8%analysed10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.8CVE-2026-24061GNU Inetutils telnetd argument injection allows remote auth bypasstelnetd in GNU Inetutils through 2.7 fails to sanitize the USER environment variable, so a value such as "-f root" is passed as an argument to login …KEVEPSS 99%analysed9.8CVE-2025-39682Linux kernel TLS zero-length record handling flaw on rx_listThe Linux kernel TLS receive path mishandles zero-length records that arrive from the rx_list, breaking the assumption that a record type change cann…KEVEPSS 2.9%analysed9.8CVE-2025-24813Apache Tomcat Default Servlet path equivalence enables RCE and file disclosureApache Tomcat mishandles path equivalence for names containing an internal dot, letting a remote unauthenticated attacker write files through the Def…KEVEPSS 100%analysed9.8CVE-2024-9680Mozilla Firefox and Thunderbird use-after-free in Animation timelinesA use-after-free flaw in Animation timelines allows an attacker to execute code in the content process of Firefox and Thunderbird. Mozilla reports ex…KEVEPSS 23%analysed9.8CVE-2024-4577PHP-CGI on Windows argument injection leads to remote code executionPHP-CGI on Windows can misinterpret characters in the command line passed to Win32 API functions when certain code pages are configured, due to Windo…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2022-1292), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.