Vulnerability record · CVE-2017-3599 · published 24 April 2017
CVE-2017-3599: MySQL Server Pluggable Auth integer overflow allows pre-auth remote DoS
Oracle · Mysql
CVE-2017-3599 is an integer overflow in MySQL Server's Pluggable Auth subcomponent, affecting versions 5.6.35 and earlier and 5.7.17 and earlier. A remote, unauthenticated attacker can send a crafted authentication packet that causes a hang or repeatable crash of the server, making it a complete denial-of-service condition. Oracle has not confirmed the third-party claim that the root cause is an integer overflow in sql/auth/sql_authentication.cc.
Description
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Pluggable Auth). Supported versions that are affected are 5.6.35 and earlier and 5.7.17 and earlier. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). NOTE: the previous information is from the April 2017 CPU. Oracle has not commented on third-party claims that this issue is an integer overflow in sql/auth/sql_authentication.cc which allows remote attackers to cause a denial of service via a crafted authentication packet.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityUnauthenticated remote network access with low attack complexity and a complete availability impact, backed by public exploit code and very high EPSS, though it is not in KEV and causes only denial of service.
What it is
CVE-2017-3599 is an integer overflow in MySQL Server's Pluggable Auth subcomponent, affecting versions 5.6.35 and earlier and 5.7.17 and earlier. A remote, unauthenticated attacker can send a crafted authentication packet that causes a hang or repeatable crash of the server, making it a complete denial-of-service condition. Oracle has not confirmed the third-party claim that the root cause is an integer overflow in sql/auth/sql_authentication.cc.
Impact
An attacker can crash or hang the MySQL server without any credentials, disrupting all applications and users that depend on that database instance. There is no confidentiality or integrity impact; only availability is affected.
Attack surface
The flaw is reachable over the network via multiple protocols on the MySQL listener, with no authentication and no user interaction required (CVSS AV:N/AC:L/PR:N/UI:N). Any host that can reach the MySQL port can attempt it.
Exploitation
CISA KEV does not list this CVE, but EPSS is very high (0.899 probability, 99.8th percentile) and public exploit references exist, including an Exploit-DB entry and a vendor-independent pre-auth remote DoS writeup. This indicates mature, widely available exploit code.
What to do
- Apply the April 2017 Oracle Critical Patch Update for MySQL Server, or upgrade to a release later than 5.6.35 / 5.7.17; apply the referenced Red Hat errata (RHSA-2017:2787, RHSA-2017:2886) where applicable.
- Restrict network access to MySQL ports (default 3306) with firewall rules and bind-address so only trusted application hosts can connect.
- Do not expose MySQL directly to untrusted networks or the internet; place it behind a proxy or VPN.
- Monitor and rate-limit authentication attempts at the network or proxy layer to reduce the ability to deliver crafted auth packets at volume.
- If patching cannot be done immediately, isolate affected instances and prepare failover capacity to absorb repeated crashes.
Detection
- Alert on MySQL server process crashes, restarts, or unexpected shutdowns, correlating them with inbound connections to the MySQL port.
- Monitor for repeated or malformed authentication packets and abnormal connection churn from single source IPs.
- Review MySQL error logs for authentication-related errors or aborts preceding a service restart.
- Track MySQL version inventory to identify instances still running 5.6.35 or earlier and 5.7.17 or earlier.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2017-3599 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-3599), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.