CVE-2017-3730
Bad (EC)DHE parameters cause a client crash
Description
In OpenSSL 1.1.0 before 1.1.0d, if a malicious server supplies bad parameters for a DHE or ECDHE key exchange then this can result in the client attempting to dereference a NULL pointer leading to a client crash. This could be exploited in a Denial of Service attack.
In plain language
AI Worth attentionThis OpenSSL issue can let an attacker crash clients during a network connection handshake, and it matters most if you use OpenSSL 1.1.0 versions before 1.1.0d.
CVE-2017-3730 is a Denial of Service in OpenSSL 1.1.0 (before 1.1.0d) where invalid (EC)DHE key-exchange parameters sent by a malicious server cause a client crash during the TLS handshake.
What to do now
- Check whether any systems use OpenSSL 1.1.0 versions earlier than 1.1.0d.
- Upgrade OpenSSL to a fixed release per your platform (Debian/SUSE/Astra: update to the vendor’s patched package versions).
- Verify services that perform outgoing TLS connections (web apps, APIs, reverse proxies) are restarted after the upgrade.
- If you cannot upgrade immediately, reduce exposure by restricting outbound TLS connections only to trusted endpoints (or block untrusted servers) until patched.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:NConfidentialityI:NIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2017-3730 and every CVE in our database. Create a free account — no credit card required.
Create Free Account