CVE-2022-4304

MEDIUM

View CSAF Summary Hitachi Energy is aware of the vulnerability, CVE-2022-4304 in the OSS component OpenSSL, that affects the GMS600 versions that are listed below. An attacker successfully exploiti...

Affects 4 products across 4 vendors.

BCS5.43
CVSS 3.15.9
EPSS16.2%
Percentile97th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, high complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, no integrity impact, no availability impact.
CWE Weakness Definitions
CWE-203: CWE-203
Related Attack Patterns (CAPEC)
CAPEC-189 Black Box Reverse Engineering
via CWE-203

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A vulnerability in the OpenSSL component of Hitachi Energy GMS600 devices could allow an attacker to recover the pre-master secret by analyzing the time taken to process trial messages.

BSID: BS-2026-GLOBAL-255963-M • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2022-4304?
A vulnerability in the OpenSSL component of Hitachi Energy GMS600 devices could allow an attacker to recover the pre-master secret by analyzing the time taken to process trial messages.
What is the CVSS score for CVE-2022-4304?
CVE-2022-4304 has CVSS 5.9 (Medium). Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N. EPSS: 16.2%.
Is CVE-2022-4304 actively exploited?
No confirmed active exploitation of CVE-2022-4304 as of 2026-05-30.
How do I remediate CVE-2022-4304?
Priority: MEDIUM. Advisory: https://www.openssl.org/news/secadv/20230207.txt PSIRT: [email protected]
What systems are affected by CVE-2022-4304?
CVE-2022-4304 affects: Fujitsu-Siemens, Openssl, Siemens, Stormshield, Stormshield, Stormshield.
Vulnerability Details
CVE IDCVE-2022-4304
BSIDBS-2026-GLOBAL-255963-M BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Published2026-05-21
Last Modified2026-05-21
ICS Relevance55%
Weakness (CWE)
Verticals
ICS-OT
SourceNVD
Official Description

View CSAF Summary Hitachi Energy is aware of the vulnerability, CVE-2022-4304 in the OSS component OpenSSL, that affects the GMS600 versions that are listed below. An attacker successfully exploiting this vulnerability could send trial messages to the server and record the time taken to process them. After a sufficiently large number of messages the attacker could recover the pre-master secret used for the original connection and thus be able to decrypt the application data sent over that connec

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The attack involves sending a large number of trial messages to the server and measuring the time taken to process each message. Over time, this timing information can be used to deduce the pre-master secret, potentially compromising the security of the encrypted communications.

Exploitation Likelihood: MEDIUM

Affected Products
VendorProductFixed Version
Fujitsu-Siemens —
Openssl Openssl
Siemens —
Stormshield Stormshield Network Security
Stormshield Endpoint Security
Stormshield Sslvpn
Remediation
View Vendor Advisory →

Remediation Priority: MEDIUM

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 65 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hash9b67f6a14a9484620cb5f73faef3c8680ceac4dfa902fe285680a44aa63f3b23368e3ea55af0f580ee404b3db32e75488c277e6005bfdae48d8f40dcae27b6a3
Related CVEs affecting Fujitsu-Siemens
CVE-2024-32741 10.0 A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0).... CVE-2024-44102 10.0 A vulnerability has been identified in PP TeleControl Server Basic 1000 to 50... CVE-2008-5810 10.0 WBPublish (aka WBPublish.exe) in Fujitsu-Siemens WebTransactions 7.0, 7.1, an... CVE-2024-30207 10.0 A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780... CVE-2025-32433 10.0 Erlang/OTP is a set of libraries for the Erlang programming language. Prior t...
View all Fujitsu-Siemens CVEs →

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.

Join free →