Vulnerability record · CVE-2017-3731 · published 4 May 2017
CVE-2017-3731: OpenSSL 32-bit out-of-bounds read crashes TLS peers
OOpenssl · Openssl
On 32-bit hosts, OpenSSL's SSL/TLS client or server can perform an out-of-bounds read when a specific cipher is in use and a truncated packet is received, usually causing a crash. OpenSSL 1.1.0 is affected via CHACHA20/POLY1305 and 1.0.2 via RC4-MD5, so unpatched 32-bit deployments are exposed to remote denial of service.
Description
If an SSL/TLS server or client is running on a 32-bit host, and a specific cipher is being used, then a truncated packet can cause that server or client to perform an out-of-bounds read, usually resulting in a crash. For OpenSSL 1.1.0, the crash can be triggered when using CHACHA20/POLY1305; users should upgrade to 1.1.0d. For Openssl 1.0.2, the crash can be triggered when using RC4-MD5; users who have not disabled that algorithm should update to 1.0.2k.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityRemote unauthenticated denial of service with a high EPSS score, though limited to 32-bit hosts using specific ciphers and with no KEV listing.
What it is
On 32-bit hosts, OpenSSL's SSL/TLS client or server can perform an out-of-bounds read when a specific cipher is in use and a truncated packet is received, usually causing a crash. OpenSSL 1.1.0 is affected via CHACHA20/POLY1305 and 1.0.2 via RC4-MD5, so unpatched 32-bit deployments are exposed to remote denial of service.
Impact
An attacker gains a remote denial of service: the affected TLS process crashes, disrupting service. The flaw is an out-of-bounds read, so no code execution or data disclosure is described.
Attack surface
Reachable over the network by sending a crafted truncated TLS packet to a 32-bit OpenSSL client or server using the affected cipher; no authentication or user interaction is required per the CVSS vector (AV:N/PR:N/UI:N).
Exploitation
Not listed in CISA KEV and no public exploit is referenced in the record, but EPSS is high (0.576, 99th percentile), indicating elevated likelihood of exploitation activity.
What to do
- Upgrade OpenSSL to 1.1.0d or 1.0.2k (or later) as directed by the vendor advisory.
- Apply vendor patches for downstream products (Red Hat, Debian, Oracle, FreeBSD, Gentoo, NetApp, Palo Alto Networks, Android, HPE) where OpenSSL is bundled.
- Disable RC4-MD5 on 1.0.2 deployments and avoid CHACHA20/POLY1305 on 1.1.0 until patched.
- Inventory 32-bit hosts running TLS services and prioritize them for patching.
Detection
- Monitor TLS service logs and crash dumps for unexpected process termination on 32-bit hosts.
- Alert on TLS handshakes negotiating RC4-MD5 or CHACHA20/POLY1305 on unpatched 32-bit endpoints.
- Track OpenSSL version strings in software inventory to find hosts below 1.1.0d or 1.0.2k.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2017-3731 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-3731), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.