CVE-2022-22576

HIGH CVSS 3.1: 8.1 EPSS 2.16%
Updated Apr 16, 2026
Brocade
Parameter Value
CVSS 8.1 (HIGH)
Affected Versions 7.33.0 — 9.0.6
Fixed In 7.83.0
Type CWE-306 (Missing Authentication for Critical Function), CWE-287 (Improper Authentication)
Vendor Brocade
Public PoC No

An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects SASL-enabled protocols: SMPTP(S), IMAP(S), POP3(S) and LDAP(S) (openldap only).

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
None
No disruption

CVSS Vector v3.1

Vulnerable Products 20

Configuration From (including) Up to (excluding)
Haxx Curl
cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*
7.33.0 7.83.0
Debian Debian_Linux
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
— —
Debian Debian_Linux
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
— —
Netapp Clustered_Data_Ontap
cpe:2.3:a:netapp:clustered_data_ontap:-:*:*:*:*:*:*:*
— —
Netapp Solidfire_\&_Hci_Management_Node
cpe:2.3:a:netapp:solidfire_\&_hci_management_node:-:*:*:*:*:*:*:*
— —
Netapp Solidfire_\&_Hci_Storage_Node
cpe:2.3:a:netapp:solidfire_\&_hci_storage_node:-:*:*:*:*:*:*:*
— —
Brocade Fabric_Operating_System
cpe:2.3:o:brocade:fabric_operating_system:-:*:*:*:*:*:*:*
— —
Netapp Bootstrap_Os
cpe:2.3:o:netapp:bootstrap_os:-:*:*:*:*:*:*:*
— —
Netapp Hci_Compute_Node
cpe:2.3:h:netapp:hci_compute_node:-:*:*:*:*:*:*:*
— —
Netapp H300s_Firmware
cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*
— —
Netapp H300s
cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:*
— —
Netapp H500s_Firmware
cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*
— —
Netapp H500s
cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:*
— —
Netapp H700s_Firmware
cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*
— —
Netapp H700s
cpe:2.3:h:netapp:h700s:-:*:*:*:*:*:*:*
— —
Netapp H410s_Firmware
cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*
— —
Netapp H410s
cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:*
— —
Splunk Universal_Forwarder
cpe:2.3:a:splunk:universal_forwarder:*:*:*:*:*:*:*:*
8.2.0 8.2.12
Splunk Universal_Forwarder
cpe:2.3:a:splunk:universal_forwarder:*:*:*:*:*:*:*:*
9.0.0 9.0.6
Splunk Universal_Forwarder
cpe:2.3:a:splunk:universal_forwarder:9.1.0:*:*:*:*:*:*:*
— —