In OpenSSL 1.1.0 before 1.1.0d, if a malicious server supplies bad parameters for a DHE or ECDHE key exchange then this can result in the client attempting to dereference a NULL pointer leading to a client crash. This could be exploited in a Denial of Service attack.
Conclusion & alert: CVE-2017-3730 is rated High Exploit Risk (84.4/100): CVSS High severity, with high exploitation likelihood (EPSS 59.22%, 98th percentile). Core evidence: 2 public exploit reference(s) are indexed (Exploit-DB). EPSS rose +6.17% over the last day, indicating growing attacker interest. Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| 41192 | exploit_db | edb | 2017-01-26 | Exploit-DB ↗ |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-31 | 53.05% | 59.22% | +6.17% |
| 2 | 2026-05-04 | 52.92% | 53.05% | +0.13% |
| 3 | 2026-03-22 | — | 52.92% | — |
Full EPSS history (61 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.0 | HIGH |
|
3.9 | 3.6 | [email protected] |
| 5.0 | 2.0 | MEDIUM |
|
10.0 | 2.9 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2017-3730 not yet assigned priority: Debian including 1 source packages (openssl), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2017-3730 |
gentoo
|
normal | CVE-2017-3730: 1 GLSA(s) (201702-07), 1 atom(s) (dev-libs/openssl); latest impact normal. | https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2017-3730 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2017-3730 |
suse
|
medium | CVE-2017-3730 severity moderate: SUSE including 14 source package names (compat-openssl097g, compat-openssl098, …), 44 product×package rows across 14 product lines (SLES for SAP Applications 11 SP3, SUSE Linux Enterprise Desktop 12 SP1, … (14 product lines)): Known Not Affected 44. | https://www.suse.com/security/cve/CVE-2017-3730/ |
ubuntu
|
medium | CVE-2017-3730 medium priority: Ubuntu including 2 source packages (openssl, openssl098), 10 status rows across 5 suites (precise, trusty, upstream, xenial, yakkety): not-affected 5, DNE 3, needs-triage 2. | https://ubuntu.com/security/CVE-2017-3730 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| openssl | openssl | 1.1.0 | cpe:2.3:a:openssl:openssl:1.1.0:*:*:*:*:*:*:* |
| openssl | openssl | 1.1.0a | cpe:2.3:a:openssl:openssl:1.1.0a:*:*:*:*:*:*:* |
| openssl | openssl | 1.1.0b | cpe:2.3:a:openssl:openssl:1.1.0b:*:*:*:*:*:*:* |
| openssl | openssl | 1.1.0c | cpe:2.3:a:openssl:openssl:1.1.0c:*:*:*:*:*:*:* |
| oracle | agile_engineering_data_management | 6.1.3 | cpe:2.3:a:oracle:agile_engineering_data_management:6.1.3:*:*:*:*:*:*:* |
| oracle | agile_engineering_data_management | 6.2.0 | cpe:2.3:a:oracle:agile_engineering_data_management:6.2.0:*:*:*:*:*:*:* |
| oracle | communications_application_session_controller | 3.7.1 | cpe:2.3:a:oracle:communications_application_session_controller:3.7.1:*:*:*:*:*:*:* |
| oracle | communications_application_session_controller | 3.8.0 | cpe:2.3:a:oracle:communications_application_session_controller:3.8.0:*:*:*:*:*:*:* |
| oracle | communications_eagle_lnp_application_processor | 10.0 | cpe:2.3:a:oracle:communications_eagle_lnp_application_processor:10.0:*:*:*:*:*:*:* |
| oracle | communications_eagle_lnp_application_processor | 10.1 | cpe:2.3:a:oracle:communications_eagle_lnp_application_processor:10.1:*:*:*:*:*:*:* |
| oracle | communications_eagle_lnp_application_processor | 10.2 | cpe:2.3:a:oracle:communications_eagle_lnp_application_processor:10.2:*:*:*:*:*:*:* |
| oracle | communications_operations_monitor | 3.4 | cpe:2.3:a:oracle:communications_operations_monitor:3.4:*:*:*:*:*:*:* |
| oracle | communications_operations_monitor | 4.0 | cpe:2.3:a:oracle:communications_operations_monitor:4.0:*:*:*:*:*:*:* |
| oracle | jd_edwards_enterpriseone_tools | 9.2 | cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:9.2:*:*:*:*:*:*:* |
| oracle | jd_edwards_world_security | a9.1 | cpe:2.3:a:oracle:jd_edwards_world_security:a9.1:*:*:*:*:*:*:* |
| oracle | jd_edwards_world_security | a9.2 | cpe:2.3:a:oracle:jd_edwards_world_security:a9.2:*:*:*:*:*:*:* |
| oracle | jd_edwards_world_security | a9.3 | cpe:2.3:a:oracle:jd_edwards_world_security:a9.3:*:*:*:*:*:*:* |
| oracle | jd_edwards_world_security | a9.4 | cpe:2.3:a:oracle:jd_edwards_world_security:a9.4:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html | Patch |
| http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html | Patch |
| http://www.securityfocus.com/bid/95812 | Broken Link Third Party Advisory VDB Entry |
| http://www.securitytracker.com/id/1037717 | Third Party Advisory VDB Entry |
| https://github.com/openssl/openssl/commit/efbe126e3ebb9123ac9d058aa2bb044261342aaa | Patch Third Party Advisory |
| https://security.gentoo.org/glsa/201702-07 | Third Party Advisory |
| https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03838en_us | Third Party Advisory |
| https://www.exploit-db.com/exploits/41192/ | Exploit Third Party Advisory VDB Entry |
| https://www.openssl.org/news/secadv/20170126.txt | Patch Vendor Advisory |
| https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html | Patch |