CVE-2017-3736 is a carry propagating bug in the x86_64 Montgomery squaring procedure within OpenSSL versions prior to 1.0.2m and 1.1.0g, specifically impacting processors with BMI1, BMI2, and ADX extensions. This vulnerability primarily affects RSA, DSA, and DH algorithms, though EC algorithms are not impacted. Rated as MEDIUM severity (CVSS 6.5), successful exploitation would require significant resources and online access to an unpatched system with persistent DH parameters and a shared private key. While attacks against RSA and DSA are considered very difficult, DH attacks are deemed just feasible, potentially leading to information disclosure (CWE-200). There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Despite its low EPSS score, the vulnerability has received some community discussion and media coverage, indicating awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.0.2, < 1.0.2mCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* | ||
>= 1.1.0, < 1.1.0gCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
There is a carry propagating bug in the x86_64 Montgomery squaring procedure in OpenSSL before 1.0.2m and 1.1.0 before 1.1.0g. No EC algorithms are affected. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH are considered just feasible (although very difficult) because most of the work necessary to deduce information about a private key may be performed offline. The amount of resources required for such an attack would be very significant and likely only accessible to a limited number of attackers. An attacker would additionally need online access to an unpatched system using the target private key in a scenario with persistent DH parameters and a private key that is shared between multiple clients. This only affects processors that support the BMI1, BMI2 and ADX extensions like Intel Broadwell (5th generation) and later or AMD Ryzen.
Nov 14, 2017openssl: bn_sqrx8x_internal carry bug on x86_64
Nov 2, 2017