CVE-2022-26083

EUVD-2022-30651
Generation of weak initialization vector in an Intel(R) IPP Cryptography software library before version 2021.5 may allow an unauthenticated user to potentially enable information disclosure via local access.
IV
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
LOCAL
HIGH
LOW
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 7.73%
Affected Products (NVD)
VendorProductVersion
intelintegrated_performance_primitives_cryptography
𝑥
< 2021.5
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
ipp-crypto
trixie
2021.12.1-1
fixed