Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2017-3736

24
FAUCET Score

CVE-2017-3736 is a carry propagating bug in the x86_64 Montgomery squaring procedure within OpenSSL versions prior to 1.0.2m and 1.1.0g, specifically impacting processors with BMI1, BMI2, and ADX extensions. This vulnerability primarily affects RSA, DSA, and DH algorithms, though EC algorithms are not impacted. Rated as MEDIUM severity (CVSS 6.5), successful exploitation would require significant resources and online access to an unpatched system with persistent DH parameters and a shared private key. While attacks against RSA and DSA are considered very difficult, DH attacks are deemed just feasible, potentially leading to information disclosure (CWE-200). There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Despite its low EPSS score, the vulnerability has received some community discussion and media coverage, indicating awareness.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.0.2, < 1.0.2mCPE matchmatch criteria
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
>= 1.1.0, < 1.1.0gCPE matchmatch criteria
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

6.5MEDIUM

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
3.6
CvssVersion
3.0

Exploit Intelligence

EPSS Score
10.13%
Probability of exploitation in next 30 days
EPSS Percentile
95.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.1013 is in the 99th percentile among its peer group of 21,958 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (36)

oraclepatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-apache-commons-daemon-0:1.1.0-1.redhat_2.1.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-apache-commons-daemon-jsvc-1:1.1.0-1.redhat_2.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-apr-0:1.6.3-14.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-apr-util-0:1.6.1-9.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-httpd-0:2.4.29-17.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-mod_auth_kerb-0:5.4-36.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-mod_bmx-0:0.9.6-17.GA.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-mod_cluster-native-0:1.3.8-1.Final_redhat_2.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-mod_jk-0:1.2.43-1.redhat_1.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-mod_rt-0:2.4.1-19.GA.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-mod_security-0:2.9.1-23.GA.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-nghttp2-0:1.29.0-8.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-openssl-1:1.0.2n-11.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-apache-commons-daemon-0:1.1.0-1.redhat_2.1.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-apache-commons-daemon-jsvc-1:1.1.0-1.redhat_2.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-apr-0:1.6.3-14.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-apr-util-0:1.6.1-9.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-httpd-0:2.4.29-17.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-mod_auth_kerb-0:5.4-36.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-mod_bmx-0:0.9.6-17.GA.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-mod_cluster-native-0:1.3.8-1.Final_redhat_2.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-mod_jk-0:1.2.43-1.redhat_1.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-mod_rt-0:2.4.1-19.GA.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-mod_security-0:2.9.1-23.GA.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-nghttp2-0:1.29.0-8.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-openssl-1:1.0.2n-11.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6 SupplementaryFixed in: java-1.8.0-ibm-1:1.8.0.5.20-1jpp.1.el6_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: openssl-1:1.0.2k-12.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7 SupplementaryFixed in: java-1.8.0-ibm-1:1.8.0.5.20-1jpp.1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Satellite 5.8Fixed in: java-1.8.0-ibm-1:1.8.0.5.20-1jpp.1.el6_10
View patch
redhatpatch availablevia redhat_api
Product: Text-Only JBCSFixed in: openssl
View patch
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: OVMF
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Virtualization 3Fixed in: mingw-virt-viewer
redhatno patchvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 6Fixed in: openssl
redhatend of lifevia redhat_api
Product: Red Hat JBoss Enterprise Web Server 2Fixed in: openssl

Vendor Advisories (2)

microsoft2017-Nov/CVE-2017-3736Moderate

There is a carry propagating bug in the x86_64 Montgomery squaring procedure in OpenSSL before 1.0.2m and 1.1.0 before 1.1.0g. No EC algorithms are affected. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH are considered just feasible (although very difficult) because most of the work necessary to deduce information about a private key may be performed offline. The amount of resources required for such an attack would be very significant and likely only accessible to a limited number of attackers. An attacker would additionally need online access to an unpatched system using the target private key in a scenario with persistent DH parameters and a private key that is shared between multiple clients. This only affects processors that support the BMI1, BMI2 and ADX extensions like Intel Broadwell (5th generation) and later or AMD Ryzen.

Nov 14, 2017
redhatCVE-2017-3736Moderate

openssl: bn_sqrx8x_internal carry bug on x86_64

Nov 2, 2017

References

access.redhat.com / errata/RHSA-2018:0998
Third Party Advisory
access.redhat.com / errata/RHSA-2018:2185
Third Party Advisory
access.redhat.com / errata/RHSA-2018:2186
Third Party Advisory
access.redhat.com / errata/RHSA-2018:2187
Third Party Advisory
access.redhat.com / errata/RHSA-2018:2568
Third Party Advisory
access.redhat.com / errata/RHSA-2018:2575
Third Party Advisory
access.redhat.com / errata/RHSA-2018:2713
Third Party Advisory
github.com / openssl/openssl/commit/4443cf7aa0099e5ce615c18cee249fff77fb0871
Third Party Advisory
security.freebsd.org / advisories/FreeBSD-SA-17:11.openssl.asc
Third Party Advisory
security.gentoo.org / glsa/201712-03
Third Party Advisory
security.netapp.com / advisory/ntap-20171107-0002
Issue TrackingThird Party Advisory
security.netapp.com / advisory/ntap-20180117-0002
Third Party Advisory
support.hpe.com / hpsc/doc/public/display
Third Party Advisory
debian.org / security/2017/dsa-4017
Issue TrackingThird Party Advisory
debian.org / security/2017/dsa-4018
Issue TrackingThird Party Advisory
openssl.org / news/secadv/20171102.txt
Issue TrackingVendor Advisory
oracle.com / technetwork/security-advisory/cpuapr2019-5072813.html
oracle.com / technetwork/security-advisory/cpujan2019-5072801.html
oracle.com / technetwork/security-advisory/cpujul2019-5072835.html
tenable.com / security/tns-2017-14
Issue TrackingThird Party Advisory
tenable.com / security/tns-2017-15
Third Party Advisory
oracle.com / technetwork/security-advisory/cpuapr2018-3678067.html
PatchThird Party Advisory
oracle.com / technetwork/security-advisory/cpujan2018-3236628.html
PatchThird Party Advisory
oracle.com / technetwork/security-advisory/cpujul2018-4258247.html
PatchThird Party Advisory
oracle.com / technetwork/security-advisory/cpuoct2018-4428296.html
PatchThird Party Advisory
securityfocus.com / bid/101666
Third Party AdvisoryVDB Entry
securitytracker.com / id/1039727
Third Party AdvisoryVDB Entry