cbcvebase.
CVE-2017-3730
published 2017-05-04

CVE-2017-3730: In OpenSSL 1.1.0 before 1.1.0d, if a malicious server supplies bad parameters for a DHE or ECDHE key exchange then this can result in the client attempting to…

PriorityP261high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EXPLOIT
EPSS
55.29%
98.9th percentile
In OpenSSL 1.1.0 before 1.1.0d, if a malicious server supplies bad parameters for a DHE or ECDHE key exchange then this can result in the client attempting to dereference a NULL pointer leading to a client crash. This could be exploited in a Denial of Service attack.

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
debianopenssl< openssl 1.1.0d-1 (bookworm)openssl 1.1.0d-1 (bookworm)
opensslopenssl
opensslopenssl
opensslopenssl
opensslopenssl
opensslopenssl
opensslopenssl
opensslopenssl
opensslopenssl
opensslopenssl>= 0 < 1.1.0d-11.1.0d-1
opensslopenssl>= 0 < 1.1.0d-11.1.0d-1
opensslopenssl>= 0 < 1.1.0d-11.1.0d-1
opensslopenssl>= 0 < 1.1.0d-11.1.0d-1
oracleagile_engineering_data_management
oracleagile_engineering_data_management
oraclecommunications_application_session_controller
oraclecommunications_application_session_controller
oraclecommunications_eagle_lnp_application_processor
oraclecommunications_eagle_lnp_application_processor
oraclecommunications_eagle_lnp_application_processor
oraclecommunications_operations_monitor
oraclecommunications_operations_monitor
oraclejd_edwards_enterpriseone_tools
oraclejd_edwards_world_security
oraclejd_edwards_world_security

Detection & IOCsextracted from sources · hover to see the quote

commandTLS-DHE-RSA-WITH-AES-256-GCM-SHA384
  • The PoC exploit impersonates an SMTP server with STARTTLS support; detect clients crashing after connecting to a rogue SMTP server that advertises STARTTLS and forces DHE-RSA key exchange with bad parameters.
  • Vulnerability is client-side only and triggered during DHE or ECDHE key exchange with a malicious server supplying bad parameters; monitor OpenSSL 1.1.0 (before 1.1.0d) client-side NULL pointer dereference crashes during TLS handshake.
  • ·The vulnerability only affects OpenSSL version 1.1.0 before 1.1.0d; versions 1.0.x and all Red Hat Enterprise Linux/JBoss packaged versions are not affected.
  • ·The vulnerability is client-side only; servers using OpenSSL 1.1.0 are not directly vulnerable unless they also act as clients.
  • ·No Cisco products were found to be affected by CVE-2017-3730.

CVSS provenance

nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_cisco7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.