Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2017-3732 | First vendor Publication | 2017-05-04 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N | |||
---|---|---|---|
Overall CVSS Score | 5.9 | ||
Base Score | 5.9 | Environmental Score | 5.9 |
impact SubScore | 3.6 | Temporal Score | 5.9 |
Exploitabality Sub Score | 2.2 | ||
Attack Vector | Network | Attack Complexity | High |
Privileges Required | None | User Interaction | None |
Scope | Unchanged | Confidentiality Impact | High |
Integrity Impact | None | Availability Impact | None |
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:P/I:N/A:N) | |||
---|---|---|---|
Cvss Base Score | 4.3 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
There is a carry propagating bug in the x86_64 Montgomery squaring procedure in OpenSSL 1.0.2 before 1.0.2k and 1.1.0 before 1.1.0d. No EC algorithms are affected. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH are considered just feasible (although very difficult) because most of the work necessary to deduce information about a private key may be performed offline. The amount of resources required for such an attack would be very significant and likely only accessible to a limited number of attackers. An attacker would additionally need online access to an unpatched system using the target private key in a scenario with persistent DH parameters and a private key that is shared between multiple clients. For example this can occur by default in OpenSSL DHE based SSL/TLS ciphersuites. Note: This issue is very similar to CVE-2015-3193 but must be treated as a separate problem. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-3732 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-200 | Information Exposure |
CPE : Common Platform Enumeration
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2018-05-11 | Name : The remote Amazon Linux AMI host is missing a security update. File : ala_ALAS-2018-1016.nasl - Type : ACT_GATHER_INFO |
2018-04-27 | Name : The remote Amazon Linux 2 host is missing a security update. File : al2_ALAS-2018-1004.nasl - Type : ACT_GATHER_INFO |
2018-02-20 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201802-04.nasl - Type : ACT_GATHER_INFO |
2017-12-18 | Name : The remote SUSE host is missing one or more security updates. File : suse_SU-2017-3343-1.nasl - Type : ACT_GATHER_INFO |
2017-12-18 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2017-1381.nasl - Type : ACT_GATHER_INFO |
2017-09-20 | Name : The remote VMware ESXi 6.0 host is affected by multiple vulnerabilities. File : vmware_esxi_6_0_build_5485776_remote.nasl - Type : ACT_GATHER_INFO |
2017-08-23 | Name : The remote device is missing a vendor-supplied security patch. File : juniper_jsa10775.nasl - Type : ACT_GATHER_INFO |
2017-07-31 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2017-866.nasl - Type : ACT_GATHER_INFO |
2017-07-20 | Name : An enterprise management application installed on the remote host is affected... File : oracle_enterprise_manager_jul_2017_cpu.nasl - Type : ACT_GATHER_INFO |
2017-06-26 | Name : The Tenable SecurityCenter application on the remote host contains an OpenSSL... File : securitycenter_openssl_1_0_2k.nasl - Type : ACT_GATHER_INFO |
2017-05-02 | Name : An application installed on the remote host is affected by multiple vulnerabi... File : oracle_secure_global_desktop_apr_2017_cpu.nasl - Type : ACT_GATHER_INFO |
2017-04-21 | Name : A web application running on the remote host is affected by multiple vulnerab... File : mysql_enterprise_monitor_3_3_3_1199.nasl - Type : ACT_GATHER_INFO |
2017-04-20 | Name : The remote database server is affected by multiple vulnerabilities. File : mysql_5_6_36_rpm.nasl - Type : ACT_GATHER_INFO |
2017-04-20 | Name : The remote database server is affected by multiple vulnerabilities. File : mysql_5_7_18_rpm.nasl - Type : ACT_GATHER_INFO |
2017-04-20 | Name : The remote database server is affected by multiple vulnerabilities. File : mysql_5_7_18.nasl - Type : ACT_GATHER_INFO |
2017-04-20 | Name : The remote database server is affected by multiple vulnerabilities. File : mysql_5_6_36.nasl - Type : ACT_GATHER_INFO |
2017-04-06 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2017-442.nasl - Type : ACT_GATHER_INFO |
2017-03-14 | Name : An application installed on the remote host is affected by multiple vulnerabi... File : securitycenter_5_4_3_tns_2017_04.nasl - Type : ACT_GATHER_INFO |
2017-02-21 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2017-284.nasl - Type : ACT_GATHER_INFO |
2017-02-21 | Name : The remote openSUSE host is missing a security update. File : openSUSE-2017-256.nasl - Type : ACT_GATHER_INFO |
2017-02-17 | Name : The remote device is missing a vendor-supplied security patch. File : f5_bigip_SOL44512851.nasl - Type : ACT_GATHER_INFO |
2017-02-15 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201702-07.nasl - Type : ACT_GATHER_INFO |
2017-02-15 | Name : The remote Fedora host is missing a security update. File : fedora_2017-e853b4144f.nasl - Type : ACT_GATHER_INFO |
2017-02-13 | Name : The remote SUSE host is missing one or more security updates. File : suse_SU-2017-0441-1.nasl - Type : ACT_GATHER_INFO |
2017-02-13 | Name : The remote Slackware host is missing a security update. File : Slackware_SSA_2017-041-02.nasl - Type : ACT_GATHER_INFO |
2017-02-08 | Name : The remote Fedora host is missing a security update. File : fedora_2017-3451dbec48.nasl - Type : ACT_GATHER_INFO |
2017-02-01 | Name : The remote Ubuntu host is missing a security-related patch. File : ubuntu_USN-3181-1.nasl - Type : ACT_GATHER_INFO |
2017-01-30 | Name : A service running on the remote host is affected by multiple vulnerabilities. File : openssl_1_1_0d.nasl - Type : ACT_GATHER_INFO |
2017-01-30 | Name : A service running on the remote host is affected by multiple vulnerabilities. File : openssl_1_0_2k.nasl - Type : ACT_GATHER_INFO |
2017-01-27 | Name : The remote FreeBSD host is missing one or more security-related updates. File : freebsd_pkg_d455708ae3d311e69940b499baebfeaf.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 13:06:58 |
|
2024-08-02 12:48:58 |
|
2024-08-02 01:13:52 |
|
2024-02-02 01:47:28 |
|
2024-02-01 12:13:16 |
|
2023-09-05 12:45:20 |
|
2023-09-05 01:13:00 |
|
2023-09-02 12:45:03 |
|
2023-09-02 01:13:17 |
|
2023-08-12 12:48:42 |
|
2023-08-12 01:12:47 |
|
2023-08-11 12:43:07 |
|
2023-08-11 01:13:08 |
|
2023-08-06 12:41:45 |
|
2023-08-06 01:12:46 |
|
2023-08-04 12:41:55 |
|
2023-08-04 01:12:50 |
|
2023-07-14 12:41:58 |
|
2023-07-14 01:12:49 |
|
2023-03-29 01:43:39 |
|
2023-03-28 12:13:05 |
|
2022-10-11 12:37:24 |
|
2022-10-11 01:12:42 |
|
2022-08-30 00:27:34 |
|
2021-05-04 13:01:39 |
|
2021-04-22 02:15:07 |
|
2020-05-23 01:00:29 |
|
2019-04-24 05:18:55 |
|
2019-04-24 00:18:53 |
|
2018-09-18 17:19:44 |
|
2018-08-29 17:20:04 |
|
2018-08-28 17:20:06 |
|
2018-07-28 09:19:20 |
|
2018-07-14 09:19:21 |
|
2018-02-14 13:21:19 |
|
2018-01-18 21:22:37 |
|
2017-12-19 13:23:50 |
|
2017-11-21 09:22:05 |
|
2017-11-03 09:21:18 |
|
2017-10-20 09:23:03 |
|
2017-09-22 13:24:46 |
|
2017-08-24 13:25:06 |
|
2017-08-09 09:23:35 |
|
2017-08-02 13:24:44 |
|
2017-07-25 09:23:11 |
|
2017-07-21 13:24:50 |
|
2017-07-01 09:23:51 |
|
2017-06-27 13:23:21 |
|
2017-05-18 00:20:38 |
|
2017-05-06 09:23:20 |
|
2017-05-05 00:23:23 |
|