CVE-2017-3730 identifies a NULL pointer dereference vulnerability in OpenSSL 1.1.0 before 1.1.0d, which can also affect products like Oracle utilizing these versions. This flaw allows a malicious server to supply bad parameters during a DHE or ECDHE key exchange, causing the client to crash and leading to a Denial of Service. With a CVSS v3 score of 7.5 (High), this vulnerability has a network-based attack vector with low complexity. Although not in CISA's KEV catalog, it is listed as "Active" on the Hot List, and public exploit code (EDB-41192) is available, indicating potential for active exploitation and notable community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.1.0CPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.1.0:*:*:*:*:*:*:* | ||
1.1.0aCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.1.0a:*:*:*:*:*:*:* | ||
1.1.0bCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.1.0b:*:*:*:*:*:*:* | ||
1.1.0cCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.1.0c:*:*:*:*:*:*:* | ||
6.1.3CPE matchmatch criteria | cpe:2.3:a:oracle:agile_engineering_data_management:6.1.3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.