// For flags

CVE-2017-3730

Bad (EC)DHE parameters cause a client crash

Severity Score

7.5
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

In OpenSSL 1.1.0 before 1.1.0d, if a malicious server supplies bad parameters for a DHE or ECDHE key exchange then this can result in the client attempting to dereference a NULL pointer leading to a client crash. This could be exploited in a Denial of Service attack.

En OpenSSL versión 1.1.0 anterior a 1.1.0d, si un servidor malicioso suministra parámetros incorrectos para un intercambio de claves DHE o ECDHE, entonces esto puede resultar en que el cliente intente desreferenciar un puntero NULL que conduce a un bloqueo del cliente. Esto podría ser explotado en un ataque de denegación de servicio.

*Credits: Guido Vranken
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2016-12-16 CVE Reserved
  • 2017-01-26 CVE Published
  • 2017-01-26 First Exploit
  • 2024-09-16 CVE Updated
  • 2024-11-16 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-476: NULL Pointer Dereference
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
1.1.0
Search vendor "Openssl" for product "Openssl" and version "1.1.0"
-
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
1.1.0a
Search vendor "Openssl" for product "Openssl" and version "1.1.0a"
-
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
1.1.0b
Search vendor "Openssl" for product "Openssl" and version "1.1.0b"
-
Affected
Openssl
Search vendor "Openssl"
Openssl
Search vendor "Openssl" for product "Openssl"
1.1.0c
Search vendor "Openssl" for product "Openssl" and version "1.1.0c"
-
Affected
Oracle
Search vendor "Oracle"
Agile Engineering Data Management
Search vendor "Oracle" for product "Agile Engineering Data Management"
6.1.3
Search vendor "Oracle" for product "Agile Engineering Data Management" and version "6.1.3"
-
Affected
Oracle
Search vendor "Oracle"
Agile Engineering Data Management
Search vendor "Oracle" for product "Agile Engineering Data Management"
6.2.0
Search vendor "Oracle" for product "Agile Engineering Data Management" and version "6.2.0"
-
Affected
Oracle
Search vendor "Oracle"
Communications Application Session Controller
Search vendor "Oracle" for product "Communications Application Session Controller"
3.7.1
Search vendor "Oracle" for product "Communications Application Session Controller" and version "3.7.1"
-
Affected
Oracle
Search vendor "Oracle"
Communications Application Session Controller
Search vendor "Oracle" for product "Communications Application Session Controller"
3.8.0
Search vendor "Oracle" for product "Communications Application Session Controller" and version "3.8.0"
-
Affected
Oracle
Search vendor "Oracle"
Communications Eagle Lnp Application Processor
Search vendor "Oracle" for product "Communications Eagle Lnp Application Processor"
10.0
Search vendor "Oracle" for product "Communications Eagle Lnp Application Processor" and version "10.0"
-
Affected
Oracle
Search vendor "Oracle"
Communications Eagle Lnp Application Processor
Search vendor "Oracle" for product "Communications Eagle Lnp Application Processor"
10.1
Search vendor "Oracle" for product "Communications Eagle Lnp Application Processor" and version "10.1"
-
Affected
Oracle
Search vendor "Oracle"
Communications Eagle Lnp Application Processor
Search vendor "Oracle" for product "Communications Eagle Lnp Application Processor"
10.2
Search vendor "Oracle" for product "Communications Eagle Lnp Application Processor" and version "10.2"
-
Affected
Oracle
Search vendor "Oracle"
Communications Operations Monitor
Search vendor "Oracle" for product "Communications Operations Monitor"
3.4
Search vendor "Oracle" for product "Communications Operations Monitor" and version "3.4"
-
Affected
Oracle
Search vendor "Oracle"
Communications Operations Monitor
Search vendor "Oracle" for product "Communications Operations Monitor"
4.0
Search vendor "Oracle" for product "Communications Operations Monitor" and version "4.0"
-
Affected
Oracle
Search vendor "Oracle"
Jd Edwards Enterpriseone Tools
Search vendor "Oracle" for product "Jd Edwards Enterpriseone Tools"
9.2
Search vendor "Oracle" for product "Jd Edwards Enterpriseone Tools" and version "9.2"
-
Affected
Oracle
Search vendor "Oracle"
Jd Edwards World Security
Search vendor "Oracle" for product "Jd Edwards World Security"
a9.1
Search vendor "Oracle" for product "Jd Edwards World Security" and version "a9.1"
-
Affected
Oracle
Search vendor "Oracle"
Jd Edwards World Security
Search vendor "Oracle" for product "Jd Edwards World Security"
a9.2
Search vendor "Oracle" for product "Jd Edwards World Security" and version "a9.2"
-
Affected
Oracle
Search vendor "Oracle"
Jd Edwards World Security
Search vendor "Oracle" for product "Jd Edwards World Security"
a9.3
Search vendor "Oracle" for product "Jd Edwards World Security" and version "a9.3"
-
Affected
Oracle
Search vendor "Oracle"
Jd Edwards World Security
Search vendor "Oracle" for product "Jd Edwards World Security"
a9.4
Search vendor "Oracle" for product "Jd Edwards World Security" and version "a9.4"
-
Affected