CVE-2022-4304
View CSAF Summary Hitachi Energy is aware of the vulnerability, CVE-2022-4304 in the OSS component OpenSSL, that affects the GMS600 versions that are listed below. An attacker successfully exploiti...
Affects 4 products across 4 vendors.
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
A vulnerability in the OpenSSL component of Hitachi Energy GMS600 devices could allow an attacker to recover the pre-master secret by analyzing the time taken to process trial messages.
BSID: BS-2026-GLOBAL-255963-M • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: MEDIUM
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2022-4304?
What is the CVSS score for CVE-2022-4304?
Is CVE-2022-4304 actively exploited?
How do I remediate CVE-2022-4304?
What systems are affected by CVE-2022-4304?
| CVE ID | CVE-2022-4304 |
|---|---|
| BSID | BS-2026-GLOBAL-255963-M BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
| Published | 2026-05-21 |
| Last Modified | 2026-05-21 |
| ICS Relevance | 55% |
| Weakness (CWE) | |
| Verticals | |
| Source | NVD |
View CSAF Summary Hitachi Energy is aware of the vulnerability, CVE-2022-4304 in the OSS component OpenSSL, that affects the GMS600 versions that are listed below. An attacker successfully exploiting this vulnerability could send trial messages to the server and record the time taken to process them. After a sufficiently large number of messages the attacker could recover the pre-master secret used for the original connection and thus be able to decrypt the application data sent over that connec
Source: NIST NVD / MITRE CVE Database
The attack involves sending a large number of trial messages to the server and measuring the time taken to process each message. Over time, this timing information can be used to deduce the pre-master secret, potentially compromising the security of the encrypted communications.
Exploitation Likelihood: MEDIUM
| Vendor | Product | Fixed Version |
|---|---|---|
| Fujitsu-Siemens | — | — |
| Openssl | Openssl | — |
| Siemens | — | — |
| Stormshield | Stormshield Network Security | — |
| Stormshield | Endpoint Security | — |
| Stormshield | Sslvpn | — |
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
SAGE Enrichment Record — provenance & audit hash
| Model | /workspace/models/qwen2.5-coder-32b-instruct-bf16 |
|---|---|
| Confidence | MEDIUM |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | 9b67f6a14a9484620cb5f73faef3c8680ceac4dfa902fe285680a44aa63f3b23368e3ea55af0f580ee404b3db32e75488c277e6005bfdae48d8f40dcae27b6a3 |
ICS/OT Vulnerability Intelligence for Your Environment
BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.
Join free →