ZeroHour

CVE-2017-3730

PoC
CVSS 3.0
7.5 high
EPSS
55%p99
Published
()
Modified
Description

In OpenSSL 1.1.0 before 1.1.0d, if a malicious server supplies bad parameters for a DHE or ECDHE key exchange then this can result in the client attempting to dereference a NULL pointer leading to a client crash. This could be exploited in a Denial of Service attack.

Vendors
openssloracle
Products
openssl, agile engineering data management, communications application session controller, communications eagle lnp application processor, communications operations monitor, jd edwards enterpriseone tools, jd edwards world security
Weakness
CWE-476
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.