← Vulnerability feed

Vulnerability record · CVE-2017-3731 · published 4 May 2017

CVE-2017-3731: OpenSSL 32-bit out-of-bounds read crashes TLS peers

OOpenssl · Openssl

On 32-bit hosts, OpenSSL's SSL/TLS client or server can perform an out-of-bounds read when a specific cipher is in use and a truncated packet is received, usually causing a crash. OpenSSL 1.1.0 is affected via CHACHA20/POLY1305 and 1.0.2 via RC4-MD5, so unpatched 32-bit deployments are exposed to remote denial of service.

7.5 CVSS 3.1 High EPSS 57% · top 1.0% CWE-125 · Out-of-bounds read
7.5CVSS 3.1 base score, v2 5.0
57%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
40References
17 Jun 2026Last modified by NVD

Description

If an SSL/TLS server or client is running on a 32-bit host, and a specific cipher is being used, then a truncated packet can cause that server or client to perform an out-of-bounds read, usually resulting in a crash. For OpenSSL 1.1.0, the crash can be triggered when using CHACHA20/POLY1305; users should upgrade to 1.1.0d. For Openssl 1.0.2, the crash can be triggered when using RC4-MD5; users who have not disabled that algorithm should update to 1.0.2k.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityRemote unauthenticated denial of service with a high EPSS score, though limited to 32-bit hosts using specific ciphers and with no KEV listing.

What it is

On 32-bit hosts, OpenSSL's SSL/TLS client or server can perform an out-of-bounds read when a specific cipher is in use and a truncated packet is received, usually causing a crash. OpenSSL 1.1.0 is affected via CHACHA20/POLY1305 and 1.0.2 via RC4-MD5, so unpatched 32-bit deployments are exposed to remote denial of service.

Impact

An attacker gains a remote denial of service: the affected TLS process crashes, disrupting service. The flaw is an out-of-bounds read, so no code execution or data disclosure is described.

Attack surface

Reachable over the network by sending a crafted truncated TLS packet to a 32-bit OpenSSL client or server using the affected cipher; no authentication or user interaction is required per the CVSS vector (AV:N/PR:N/UI:N).

Exploitation

Not listed in CISA KEV and no public exploit is referenced in the record, but EPSS is high (0.576, 99th percentile), indicating elevated likelihood of exploitation activity.

What to do

  • Upgrade OpenSSL to 1.1.0d or 1.0.2k (or later) as directed by the vendor advisory.
  • Apply vendor patches for downstream products (Red Hat, Debian, Oracle, FreeBSD, Gentoo, NetApp, Palo Alto Networks, Android, HPE) where OpenSSL is bundled.
  • Disable RC4-MD5 on 1.0.2 deployments and avoid CHACHA20/POLY1305 on 1.1.0 until patched.
  • Inventory 32-bit hosts running TLS services and prioritize them for patching.

Detection

  • Monitor TLS service logs and crash dumps for unexpected process termination on 32-bit hosts.
  • Alert on TLS handshakes negotiating RC4-MD5 or CHACHA20/POLY1305 on unpatched 32-bit endpoints.
  • Track OpenSSL version strings in software inventory to find hosts below 1.1.0d or 1.0.2k.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://rhn.redhat.com/errata/RHSA-2017-0286.html Third Party Advisory
http://www.debian.org/security/2017/dsa-3773 Third Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html PatchThird Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html PatchThird Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html PatchThird Party Advisory
http://www.securityfocus.com/bid/95813 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1037717 Third Party AdvisoryVDB Entry
https://access.redhat.com/errata/RHSA-2018:2185 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:2186 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:2187 Third Party Advisory
https://github.com/openssl/openssl/commit/00d965474b22b54e4275232bc71ee0c699c5cd21 Third Party Advisory
https://security.FreeBSD.org/advisories/FreeBSD-SA-17:02.openssl.asc Third Party Advisory
https://security.gentoo.org/glsa/201702-07 Third Party Advisory
https://security.netapp.com/advisory/ntap-20171019-0002/ Third Party Advisory
https://security.paloaltonetworks.com/CVE-2017-3731 Third Party Advisory
https://source.android.com/security/bulletin/pixel/2017-11-01 Third Party Advisory
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03838en_us Third Party Advisory
https://www.openssl.org/news/secadv/20170126.txt Vendor Advisory
https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html PatchThird Party Advisory
https://www.tenable.com/security/tns-2017-04 Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2017-0286.html Third Party Advisory
http://www.debian.org/security/2017/dsa-3773 Third Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html PatchThird Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html PatchThird Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html PatchThird Party Advisory
http://www.securityfocus.com/bid/95813 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1037717 Third Party AdvisoryVDB Entry
https://access.redhat.com/errata/RHSA-2018:2185 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:2186 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:2187 Third Party Advisory
https://github.com/openssl/openssl/commit/00d965474b22b54e4275232bc71ee0c699c5cd21 Third Party Advisory
https://security.FreeBSD.org/advisories/FreeBSD-SA-17:02.openssl.asc Third Party Advisory
https://security.gentoo.org/glsa/201702-07 Third Party Advisory
https://security.netapp.com/advisory/ntap-20171019-0002/ Third Party Advisory
https://security.paloaltonetworks.com/CVE-2017-3731 Third Party Advisory
https://source.android.com/security/bulletin/pixel/2017-11-01 Third Party Advisory
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03838en_us Third Party Advisory
https://www.openssl.org/news/secadv/20170126.txt Vendor Advisory
https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html PatchThird Party Advisory
https://www.tenable.com/security/tns-2017-04 Third Party Advisory

Track CVE-2017-3731 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed7.5CVE-2014-0160OpenSSL TLS/DTLS Heartbeat Extension Out-of-Bounds Read (Heartbleed)OpenSSL 1.0.1 before 1.0.1g mishandles Heartbeat Extension packets in its TLS and DTLS implementations, causing an out-of-bounds read of process memo…KEVEPSS 100%analysed10.0CVE-2026-21636Nodejs node.js improper access control vulnerabilityA flaw in Node.js's permission model allows Unix Domain Socket (UDS) connections to bypass network restrictions when `--permission` is enabled. Even …EPSS 0.88%10.0CVE-2015-0278Fedoraproject fedora vulnerabilitylibuv before 0.10.34 does not properly drop group privileges, which allows context-dependent attackers to gain privileges via unspecified vectors.EPSS 3.2%10.0CVE-2009-3245Openssl improper input validation vulnerabilityOpenSSL before 0.9.8m does not check for a NULL return value from bn_wexpand function calls in (1) crypto/bn/bn_div.c, (2) crypto/bn/bn_gf2m.c, (3) c…EPSS 6.5%10.0CVE-2006-3738OpenSSL SSL_get_shared_ciphers buffer overflow via long cipher listOpenSSL versions before 0.9.7l and 0.9.8d contain a buffer overflow in the SSL_get_shared_ciphers function, triggered by a long list of ciphers. The …EPSS 49%analysed9.8CVE-2026-63073Openssl vulnerabilityIssue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished name directly as the format string to `ERR_raise_da…EPSS 1.2%9.8CVE-2026-48930Nodejs node.js improper access control vulnerabilityA flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolve…EPSS 0.32%

Source: NIST National Vulnerability Database (record CVE-2017-3731), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.