CVE-2017-3730
published 2017-05-04CVE-2017-3730: In OpenSSL 1.1.0 before 1.1.0d, if a malicious server supplies bad parameters for a DHE or ECDHE key exchange then this can result in the client attempting to…
PriorityP261high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EXPLOIT
EPSS
55.29%
98.9th percentile
In OpenSSL 1.1.0 before 1.1.0d, if a malicious server supplies bad parameters for a DHE or ECDHE key exchange then this can result in the client attempting to dereference a NULL pointer leading to a client crash. This could be exploited in a Denial of Service attack.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openssl | < openssl 1.1.0d-1 (bookworm) | openssl 1.1.0d-1 (bookworm) |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | — | — |
| openssl | openssl | >= 0 < 1.1.0d-1 | 1.1.0d-1 |
| openssl | openssl | >= 0 < 1.1.0d-1 | 1.1.0d-1 |
| openssl | openssl | >= 0 < 1.1.0d-1 | 1.1.0d-1 |
| openssl | openssl | >= 0 < 1.1.0d-1 | 1.1.0d-1 |
| oracle | agile_engineering_data_management | — | — |
| oracle | agile_engineering_data_management | — | — |
| oracle | communications_application_session_controller | — | — |
| oracle | communications_application_session_controller | — | — |
| oracle | communications_eagle_lnp_application_processor | — | — |
| oracle | communications_eagle_lnp_application_processor | — | — |
| oracle | communications_eagle_lnp_application_processor | — | — |
| oracle | communications_operations_monitor | — | — |
| oracle | communications_operations_monitor | — | — |
| oracle | jd_edwards_enterpriseone_tools | — | — |
| oracle | jd_edwards_world_security | — | — |
| oracle | jd_edwards_world_security | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The PoC exploit impersonates an SMTP server with STARTTLS support; detect clients crashing after connecting to a rogue SMTP server that advertises STARTTLS and forces DHE-RSA key exchange with bad parameters. ↗
- →Vulnerability is client-side only and triggered during DHE or ECDHE key exchange with a malicious server supplying bad parameters; monitor OpenSSL 1.1.0 (before 1.1.0d) client-side NULL pointer dereference crashes during TLS handshake. ↗
- ·The vulnerability only affects OpenSSL version 1.1.0 before 1.1.0d; versions 1.0.x and all Red Hat Enterprise Linux/JBoss packaged versions are not affected. ↗
- ·The vulnerability is client-side only; servers using OpenSSL 1.1.0 are not directly vulnerable unless they also act as clients. ↗
- ·No Cisco products were found to be affected by CVE-2017-3730. ↗
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_cisco7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: January and February 2017
vendor_cisco·2017-01-31·CVSS 7.5
CVE-2017-3730 [HIGH] CWE-310 Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: January and February 2017
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: January and February 2017
On January 26, 2017, the OpenSSL Software Foundation released a security advisory that included three new vulnerabilities. The foundation also released one vulnerability that was already disclosed in the OpenSSL advisory for November 2016 and included in the Cisco Security Advisory Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: November 2016. OpenSSL classifies all the new vulnerabilities as “Moderate Severity.”
The first vulnerability affects only OpenSSL used on 32-bit systems architecture and may cause OpenSSL to crash. The second vulnerability affects only version 1.1.0 and occurs only when OpenSSL is used on the client side. The second vulnerability may cause OpenSSL to crash when
Red Hat
openssl: Bad (EC)DHE parameters cause a client crash
vendor_redhat·2017-01-26·CVSS 7.5
CVE-2017-3730 [HIGH] CWE-476 openssl: Bad (EC)DHE parameters cause a client crash
openssl: Bad (EC)DHE parameters cause a client crash
In OpenSSL 1.1.0 before 1.1.0d, if a malicious server supplies bad parameters for a DHE or ECDHE key exchange then this can result in the client attempting to dereference a NULL pointer leading to a client crash. This could be exploited in a Denial of Service attack.
Package: openssl (Red Hat Enterprise Linux 5) - Not affected
Package: openssl097a (Red Hat Enterprise Linux 5) - Not affected
Package: openssl (Red Hat Enterprise Linux 6) - Not affected
Package: openssl098e (Red Hat Enterprise Linux 6) - Not affected
Package: openssl (Red Hat Enterprise Linux 7) - Not affected
Package: openssl098e (Red Hat Enterprise Linux 7) - Not affected
Package: OVMF (Red Hat Enterprise Linux 7) - Not affected
Package: mingw-virt-viewer (Red Ha
Debian
CVE-2017-3730: openssl - In OpenSSL 1.1.0 before 1.1.0d, if a malicious server supplies bad parameters fo...
vendor_debian·2017·CVSS 7.5
CVE-2017-3730 [HIGH] CVE-2017-3730: openssl - In OpenSSL 1.1.0 before 1.1.0d, if a malicious server supplies bad parameters fo...
In OpenSSL 1.1.0 before 1.1.0d, if a malicious server supplies bad parameters for a DHE or ECDHE key exchange then this can result in the client attempting to dereference a NULL pointer leading to a client crash. This could be exploited in a Denial of Service attack.
Scope: local
bookworm: resolved (fixed in 1.1.0d-1)
bullseye: resolved (fixed in 1.1.0d-1)
forky: resolved (fixed in 1.1.0d-1)
sid: resolved (fixed in 1.1.0d-1)
trixie: resolved (fixed in 1.1.0d-1)
Cisco
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: January and February 2017
vendor_cisco
CVE-2017-3733 Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: January and February 2017
CVE-2017-3733: Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: January and February 2017
On January 26, 2017, the OpenSSL Software Foundation released a security advisory that included three new vulnerabilities. The foundation also released one vulnerability that was already disclosed in the OpenSSL advisory for November 2016 and included in the Cisco Security Advisory Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: November 2016 . OpenSSL classifies all the new vulnerabilities as “Moderate Severity.” The first vulnerability affects only OpenSSL used on 32-bit systems architecture and may cause OpenSSL to crash. The second vulnerability affects only version 1.1.0 and occurs only when OpenSSL is used on the client side. The second vulnerability may cause OpenSSL
Cisco
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: January and February 2017
vendor_cisco
CVE-2017-3732 Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: January and February 2017
CVE-2017-3732: Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: January and February 2017
On January 26, 2017, the OpenSSL Software Foundation released a security advisory that included three new vulnerabilities. The foundation also released one vulnerability that was already disclosed in the OpenSSL advisory for November 2016 and included in the Cisco Security Advisory Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: November 2016 . OpenSSL classifies all the new vulnerabilities as “Moderate Severity.” The first vulnerability affects only OpenSSL used on 32-bit systems architecture and may cause OpenSSL to crash. The second vulnerability affects only version 1.1.0 and occurs only when OpenSSL is used on the client side. The second vulnerability may cause OpenSSL
Cisco
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: January and February 2017
vendor_cisco
CVE-2017-3730 Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: January and February 2017
CVE-2017-3730: Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: January and February 2017
On January 26, 2017, the OpenSSL Software Foundation released a security advisory that included three new vulnerabilities. The foundation also released one vulnerability that was already disclosed in the OpenSSL advisory for November 2016 and included in the Cisco Security Advisory Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: November 2016 . OpenSSL classifies all the new vulnerabilities as “Moderate Severity.” The first vulnerability affects only OpenSSL used on 32-bit systems architecture and may cause OpenSSL to crash. The second vulnerability affects only version 1.1.0 and occurs only when OpenSSL is used on the client side. The second vulnerability may cause OpenSSL
Cisco
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: January and February 2017
vendor_cisco
CVE-2017-3731 Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: January and February 2017
CVE-2017-3731: Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: January and February 2017
On January 26, 2017, the OpenSSL Software Foundation released a security advisory that included three new vulnerabilities. The foundation also released one vulnerability that was already disclosed in the OpenSSL advisory for November 2016 and included in the Cisco Security Advisory Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: November 2016 . OpenSSL classifies all the new vulnerabilities as “Moderate Severity.” The first vulnerability affects only OpenSSL used on 32-bit systems architecture and may cause OpenSSL to crash. The second vulnerability affects only version 1.1.0 and occurs only when OpenSSL is used on the client side. The second vulnerability may cause OpenSSL
GHSA
GHSA-rq64-8m54-26j4: In OpenSSL 1
ghsa_unreviewed·2022-05-14
CVE-2017-3730 [HIGH] CWE-476 GHSA-rq64-8m54-26j4: In OpenSSL 1
In OpenSSL 1.1.0 before 1.1.0d, if a malicious server supplies bad parameters for a DHE or ECDHE key exchange then this can result in the client attempting to dereference a NULL pointer leading to a client crash. This could be exploited in a Denial of Service attack.
OSV
CVE-2017-3730: In OpenSSL 1
osv·2017-05-04·CVSS 7.5
CVE-2017-3730 [HIGH] CVE-2017-3730: In OpenSSL 1
In OpenSSL 1.1.0 before 1.1.0d, if a malicious server supplies bad parameters for a DHE or ECDHE key exchange then this can result in the client attempting to dereference a NULL pointer leading to a client crash. This could be exploited in a Denial of Service attack.
No detection rules found.
HackerOne
CVE-2017-3730: Bad (EC)DHE parameters cause a client crash
hackerone·2017-02-07·CVSS 7.5
CVE-2017-3730 [HIGH] CVE-2017-3730: Bad (EC)DHE parameters cause a client crash
CVE-2017-3730: Bad (EC)DHE parameters cause a client crash
https://www.openssl.org/news/secadv/20170126.txt
https://guidovranken.wordpress.com/2017/01/26/cve-2017-3730-openssl-1-1-0-remote-client-denial-of-service-affects-servers-as-well-poc/
Severity: Moderate
If a malicious server supplies bad parameters for a DHE or ECDHE key exchange then this can result in the client attempting to dereference a NULL pointer leading to a client crash. This could be exploited in a Denial of Service attack.
OpenSSL 1.1.0 users should upgrade to 1.1.0d
This issue does not affect OpenSSL version 1.0.2.
Note that this issue was fixed prior to it being recognised as a security concern. This means the git commit with the fix does not contain the CVE identifier. The relevant fix commit can be identified
Bugzilla
CVE-2017-3730 openssl: Bad (EC)DHE parameters cause a client crash
bugzilla·2017-01-26·CVSS 7.5
CVE-2017-3730 [HIGH] CVE-2017-3730 openssl: Bad (EC)DHE parameters cause a client crash
CVE-2017-3730 openssl: Bad (EC)DHE parameters cause a client crash
If a malicious server supplies bad parameters for a DHE or ECDHE key exchange
then this can result in the client attempting to dereference a NULL pointer
leading to a client crash. This could be exploited in a Denial of Service
attack.
This issue does not affect OpenSSL version 1.0.2.
External References:
https://www.openssl.org/news/secadv/20170126.txt
Discussion:
Upstream commit:
https://git.openssl.org/?p=openssl.git;a=commitdiff;h=efbe126e3ebb9123ac9d058aa2bb044261342aaa
Write up from the original reporter:
https://guidovranken.wordpress.com/2017/01/26/cve-2017-3730-openssl-1-1-0-remote-client-denial-of-service-affects-servers-as-well-poc/
---
This only affected OpenSSL 1.1.0, which is not currently included
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.securityfocus.com/bid/95812http://www.securitytracker.com/id/1037717https://github.com/openssl/openssl/commit/efbe126e3ebb9123ac9d058aa2bb044261342aaahttps://security.gentoo.org/glsa/201702-07https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03838en_ushttps://www.exploit-db.com/exploits/41192/https://www.openssl.org/news/secadv/20170126.txthttps://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.securityfocus.com/bid/95812http://www.securitytracker.com/id/1037717https://github.com/openssl/openssl/commit/efbe126e3ebb9123ac9d058aa2bb044261342aaahttps://security.gentoo.org/glsa/201702-07https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03838en_ushttps://www.exploit-db.com/exploits/41192/https://www.openssl.org/news/secadv/20170126.txthttps://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
2017-05-04
Published