CVE-2017-3169 is a critical NULL pointer dereference vulnerability in Apache httpd versions 2.2.x before 2.2.33 and 2.4.x before 2.4.26, specifically within the mod_ssl module. This flaw occurs when third-party modules invoke ap_hook_process_connection() during an HTTP request to an HTTPS port. With a CVSS score of 9.8, it presents a critical risk, allowing unauthenticated attackers to achieve high impact on confidentiality, integrity, and availability with low attack complexity. Despite its severity and high FAUCET Risk Score of 96/100, there is no evidence of active exploitation, nor are there publicly available exploits in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, suggesting limited public attention to this specific vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.2.0CPE matchmatch criteria | cpe:2.3:a:apache:http_server:2.2.0:*:*:*:*:*:*:* | ||
2.2.2CPE matchmatch criteria | cpe:2.3:a:apache:http_server:2.2.2:*:*:*:*:*:*:* | ||
2.2.3CPE matchmatch criteria | cpe:2.3:a:apache:http_server:2.2.3:*:*:*:*:*:*:* | ||
2.2.11CPE matchmatch criteria | cpe:2.3:a:apache:http_server:2.2.11:*:*:*:*:*:*:* | ||
2.2.12CPE matchmatch criteria | cpe:2.3:a:apache:http_server:2.2.12:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Mar 2, 2026Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Dec 10, 2025httpd: mod_ssl NULL pointer dereference
Jun 20, 2017Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project