peter bassill · operator
$ cve CVE-2017-3730 JSON

CVE-2017-3730 EXPLOIT

7.5
HIGH · CVSS 3.0 · EPSS 55.3% (pctl 99)

Patch early

A public exploit exists.

Description

In OpenSSL 1.1.0 before 1.1.0d, if a malicious server supplies bad parameters for a DHE or ECDHE key exchange then this can result in the client attempting to dereference a NULL pointer leading to a client crash. This could be exploited in a Denial of Service attack.

Scoring

CVSS7.5 (HIGH, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS55.29% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-476
On CISA KEVno
Public exploityes
Published2017-05-04
Last modified2026-06-17

Affected (7)

VendorProduct
opensslopenssl
oracleagile engineering data management
oraclecommunications application session controller
oraclecommunications eagle lnp application processor
oraclecommunications operations monitor
oraclejd edwards enterpriseone tools
oraclejd edwards world security

Public exploits

SourceTitleDate
exploit-dbOpenSSL 1.1.0 - Remote Client Denial of Service2017-01-26

References

→ the Explorer  ·  watch your stack  ·  NVD