{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-01T16:23:49.249","vulnerabilities":[{"cve":{"id":"CVE-2017-3738","sourceIdentifier":"openssl-security@openssl.org","published":"2017-12-07T16:29:00.240","lastModified":"2026-06-17T01:18:49.583","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"There is an overflow bug in the AVX2 Montgomery multiplication procedure used in exponentiation with 1024-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH1024 are considered just feasible, because most of the work necessary to deduce information about a private key may be performed offline. The amount of resources required for such an attack would be significant. However, for an attack on TLS to be meaningful, the server would have to share the DH1024 private key among multiple clients, which is no longer an option since CVE-2016-0701. This only affects processors that support the AVX2 but not ADX extensions like Intel Haswell (4th generation). Note: The impact from this issue is similar to CVE-2017-3736, CVE-2017-3732 and CVE-2015-3193. OpenSSL version 1.0.2-1.0.2m and 1.1.0-1.1.0g are affected. Fixed in OpenSSL 1.0.2n. Due to the low severity of this issue we are not issuing a new release of OpenSSL 1.1.0 at this time. The fix will be included in OpenSSL 1.1.0h when it becomes available. The fix is also available in commit e502cc86d in the OpenSSL git repository."},{"lang":"es","value":"Existe un error de desbordamiento en el procedimiento de multiplicación AVX2 Montgomery empleado en la exponenciación con módulos de 1024 bits. Los algoritmos EC no se han visto afectados. Los análisis sugieren que los ataques contra RSA y DSA como resultado de este defecto serían muy difíciles de realizar y se cree que son improbables. Los ataques contra DH102 se consideran solo posibles, ya que la mayor parte del trabajo necesario para deducir información sobre una clave privada puede realizarse sin conexión. La cantidad de recursos necesarios para realizar tal ataque sería significativa. Sin embargo, para que un ataque sobre TLS sea significativo, el servidor tendría que compartir la clave privada DH1024 entre múltiples clientes, lo que ya no es una opción desde CVE-2016-0701. Esto solo afecta a procesadores compatibles con la extensión AVX2, pero no la ADX, como Intel Haswell (cuarta generación). Nota: El impacto de este problema es similar a CVE-2017-3736, CVE-2017-3732 y CVE-2015-3193. Se han visto afectadas las versiones 1.0.2-1.0.2m y 1.1.0-1.1.0g de OpenSSL. Se ha solucionado en OpenSSL 1.0.2n. Debido a la baja gravedad de este problema, no se va a lanzar una nueva versión de OpenSSL 1.1.0 en este momento. La corrección se aplicará en OpenSSL 1.1.0h cuando esté disponible. La corrección también estará disponible en el commit con ID e502cc86d en el repositorio Git de OpenSSL."}],"affected":[{"source":"openssl-security@openssl.org","affectedData":[{"vendor":"OpenSSL Software Foundation","product":"OpenSSL","versions":[{"version":"1.0.2-1.02m","status":"affected"},{"version":"1.1.0-1.1.0g","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-200"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:openssl:openssl:1.0.2:*:*:*:*:*:*:*","matchCriteriaId":"AD3E5C1B-EC63-4214-A0BD-0B8681CE6C8B"},{"vulnerable":true,"criteria":"cpe:2.3:a:openssl:openssl:1.0.2:beta1:*:*:*:*:*:*","matchCriteriaId":"18797BEE-417D-4959-9AAD-C5A7C051B524"},{"vulnerable":true,"criteria":"cpe:2.3:a:openssl:openssl:1.0.2:beta2:*:*:*:*:*:*","matchCriteriaId":"6FAA3C31-BD9D-45A9-A502-837FECA6D479"},{"vulnerable":true,"criteria":"cpe:2.3:a:openssl:openssl:1.0.2:beta3:*:*:*:*:*:*","matchCriteriaId":"6455A421-9956-4846-AC7C-3431E0D37D23"},{"vulnerable":true,"criteria":"cpe:2.3:a:openssl:openssl:1.0.2a:*:*:*:*:*:*:*","matchCriteriaId":"60F946FD-F564-49DA-B043-5943308BA9EE"},{"vulnerable":true,"criteria":"cpe:2.3:a:openssl:openssl:1.0.2b:*:*:*:*:*:*:*","matchCriteriaId":"4847BCF3-EFCE-41AF-8E7D-3D51EB9DCC5B"},{"vulnerable":true,"criteria":"cpe:2.3:a:openssl:openssl:1.0.2c:*:*:*:*:*:*:*","matchCriteriaId":"9B89180B-FB68-4DD8-B076-16E51CC7FB91"},{"vulnerable":true,"criteria":"cpe:2.3:a:openssl:openssl:1.0.2d:*:*:*:*:*:*:*","matchCriteriaId":"4C986592-4086-4A39-9767-EF34DBAA6A53"},{"vulnerable":true,"criteria":"cpe:2.3:a:openssl:openssl:1.0.2e:*:*:*:*:*:*:*","matchCriteriaId":"7B23181C-03DB-4E92-B3F6-6B585B5231B4"},{"vulnerable":true,"criteria":"cpe:2.3:a:openssl:openssl:1.0.2f:*:*:*:*:*:*:*","matchCriteriaId":"94D9EC1C-4843-4026-9B05-E060E9391734"},{"vulnerable":true,"criteria":"cpe:2.3:a:openssl:openssl:1.0.2g:*:*:*:*:*:*:*","matchCriteriaId":"B066401C-21CF-4BE9-9C55-C9F1E0C7BE3F"},{"vulnerable":true,"criteria":"cpe:2.3:a:openssl:openssl:1.0.2h:*:*:*:*:*:*:*","matchCriteriaId":"036FB24F-7D86-4730-8BC9-722875BEC807"},{"vulnerable":true,"criteria":"cpe:2.3:a:openssl:openssl:1.0.2i:*:*:*:*:*:*:*","matchCriteriaId":"FDF148A3-1AA7-4F27-85AB-414C609C626F"},{"vulnerable":true,"criteria":"cpe:2.3:a:openssl:openssl:1.0.2j:*:*:*:*:*:*:*","matchCriteriaId":"E15B749E-6808-4788-AE42-7A1587D8697E"},{"vulnerable":true,"criteria":"cpe:2.3:a:openssl:openssl:1.0.2k:*:*:*:*:*:*:*","matchCriteriaId":"58F80C8D-BCA2-40AD-BD22-B70C7BE1B298"},{"vulnerable":true,"criteria":"cpe:2.3:a:openssl:openssl:1.0.2l:*:*:*:*:*:*:*","matchCriteriaId":"70B78EDF-6BB7-42C4-9423-9332C62C6E43"},{"vulnerable":true,"criteria":"cpe:2.3:a:openssl:openssl:1.0.2m:*:*:*:*:*:*:*","matchCriteriaId":"E2354F82-A01B-43D2-84F4-4E94B258E091"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:openssl:openssl:1.1.0:*:*:*:*:*:*:*","matchCriteriaId":"73104834-5810-48DD-9B97-549D223853F1"},{"vulnerable":true,"criteria":"cpe:2.3:a:openssl:openssl:1.1.0a:*:*:*:*:*:*:*","matchCriteriaId":"C9D7A18A-116B-4F68-BEA3-A4E9DDDA55C6"},{"vulnerable":true,"criteria":"cpe:2.3:a:openssl:openssl:1.1.0b:*:*:*:*:*:*:*","matchCriteriaId":"CFC70262-0DCD-4B46-9C96-FD18D0207511"},{"vulnerable":true,"criteria":"cpe:2.3:a:openssl:openssl:1.1.0c:*:*:*:*:*:*:*","matchCriteriaId":"B2E07A34-08A0-4765-AF81-46A3BDC5648A"},{"vulnerable":true,"criteria":"cpe:2.3:a:openssl:openssl:1.1.0d:*:*:*:*:*:*:*","matchCriteriaId":"83B0A3D8-60C7-4F42-9DD6-C535F983D98B"},{"vulnerable":true,"criteria":"cpe:2.3:a:openssl:openssl:1.1.0e:*:*:*:*:*:*:*","matchCriteriaId":"CD08E859-BB6D-4909-A873-C2609FA2821A"},{"vulnerable":true,"criteria":"cpe:2.3:a:openssl:openssl:1.1.0f:*:*:*:*:*:*:*","matchCriteriaId":"C2BF7D67-EAF4-4D01-9185-0DB69F2C543B"},{"vulnerable":true,"criteria":"cpe:2.3:a:openssl:openssl:1.1.0g:*:*:*:*:*:*:*","matchCriteriaId":"179144A7-D263-4BD8-A019-35DE39C777FC"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*","matchCriteriaId":"C11E6FB0-C8C0-4527-9AA0-CB9B316F8F43"},{"vulnerable":true,"criteria":"cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*","matchCriteriaId":"DEECE5FC-CACF-4496-A3E7-164736409252"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:*","versionStartIncluding":"4.0.0","versionEndIncluding":"4.1.2","matchCriteriaId":"A47FC4F7-1F77-4314-B4B3-3C5D8E335379"},{"vulnerable":true,"criteria":"cpe:2.3:a:nodejs:node.js:*:*:*:*:lts:*:*:*","versionStartIncluding":"4.2.0","versionEndExcluding":"4.8.7","matchCriteriaId":"3818E441-8DC4-42E6-8D11-E58D195CBE8A"},{"vulnerable":true,"criteria":"cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:*","versionStartIncluding":"6.0.0","versionEndIncluding":"6.8.1","matchCriteriaId":"D107EC29-67E7-40C3-8E5A-324C9105C5E4"},{"vulnerable":true,"criteria":"cpe:2.3:a:nodejs:node.js:*:*:*:*:lts:*:*:*","versionStartIncluding":"6.9.0","versionEndExcluding":"6.12.2","matchCriteriaId":"BEA03114-7288-4E7C-9220-C0ABCD5F0389"},{"vulnerable":true,"criteria":"cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:*","versionStartIncluding":"8.0.0","versionEndIncluding":"8.8.1","matchCriteriaId":"74FB695D-2C76-47AB-988E-5629D2E695E5"},{"vulnerable":true,"criteria":"cpe:2.3:a:nodejs:node.js:*:*:*:*:lts:*:*:*","versionStartIncluding":"8.9.0","versionEndExcluding":"8.9.3","matchCriteriaId":"C45E9D50-CD3D-480B-B9B8-451ADFF26505"},{"vulnerable":true,"criteria":"cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:*","versionStartIncluding":"9.0.0","versionEndExcluding":"9.2.1","matchCriteriaId":"82FDBB10-3298-4C9A-9CC0-D34643AEC868"}]}]}],"references":[{"url":"http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html","source":"openssl-security@openssl.org","tags":["Patch","Third Party Advisory"]},{"url":"http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html","source":"openssl-security@openssl.org","tags":["Patch","Third Party Advisory"]},{"url":"http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html","source":"openssl-security@openssl.org","tags":["Patch","Third Party Advisory"]},{"url":"http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html","source":"openssl-security@openssl.org","tags":["Patch","Third Party Advisory"]},{"url":"http://www.securityfocus.com/bid/102118","source":"openssl-security@openssl.org","tags":["Third Party Advisory","VDB Entry"]},{"url":"http://www.securitytracker.com/id/1039978","source":"openssl-security@openssl.org","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://access.redhat.com/errata/RHSA-2018:0998","source":"openssl-security@openssl.org","tags":["Third Party Advisory"]},{"url":"https://access.redhat.com/errata/RHSA-2018:2185","source":"openssl-security@openssl.org","tags":["Third Party Advisory"]},{"url":"https://access.redhat.com/errata/RHSA-2018:2186","source":"openssl-security@openssl.org","tags":["Third Party Advisory"]},{"url":"https://access.redhat.com/errata/RHSA-2018:2187","source":"openssl-security@openssl.org","tags":["Third Party Advisory"]},{"url":"https://github.com/openssl/openssl/commit/e502cc86df9dafded1694fceb3228ee34d11c11a","source":"openssl-security@openssl.org","tags":["Patch","Third Party Advisory"]},{"url":"https://nodejs.org/en/blog/vulnerability/december-2017-security-releases/","source":"openssl-security@openssl.org","tags":["Vendor Advisory"]},{"url":"https://security.FreeBSD.org/advisories/FreeBSD-SA-17:12.openssl.asc","source":"openssl-security@openssl.org","tags":["Third Party Advisory"]},{"url":"https://security.gentoo.org/glsa/201712-03","source":"openssl-security@openssl.org","tags":["Third Party Advisory"]},{"url":"https://security.netapp.com/advisory/ntap-20171208-0001/","source":"openssl-security@openssl.org","tags":["Third Party Advisory"]},{"url":"https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst03881en_us","source":"openssl-security@openssl.org","tags":["Third Party Advisory"]},{"url":"https://www.debian.org/security/2017/dsa-4065","source":"openssl-security@openssl.org","tags":["Third Party Advisory"]},{"url":"https://www.debian.org/security/2018/dsa-4157","source":"openssl-security@openssl.org","tags":["Third Party Advisory"]},{"url":"https://www.openssl.org/news/secadv/20171207.txt","source":"openssl-security@openssl.org","tags":["Vendor Advisory"]},{"url":"https://www.openssl.org/news/secadv/20180327.txt","source":"openssl-security@openssl.org","tags":["Vendor Advisory"]},{"url":"https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html","source":"openssl-security@openssl.org","tags":["Patch","Third Party Advisory"]},{"url":"https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html","source":"openssl-security@openssl.org","tags":["Patch","Third Party Advisory"]},{"url":"https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","source":"openssl-security@openssl.org","tags":["Patch","Third Party Advisory"]},{"url":"https://www.tenable.com/security/tns-2017-16","source":"openssl-security@openssl.org","tags":["Third Party Advisory"]},{"url":"https://www.tenable.com/security/tns-2018-04","source":"openssl-security@openssl.org","tags":["Third Party Advisory"]},{"url":"https://www.tenable.com/security/tns-2018-06","source":"openssl-security@openssl.org","tags":["Third Party Advisory"]},{"url":"https://www.tenable.com/security/tns-2018-07","source":"openssl-security@openssl.org","tags":["Third Party Advisory"]},{"url":"http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"]},{"url":"http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"]},{"url":"http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"]},{"url":"http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"]},{"url":"http://www.securityfocus.com/bid/102118","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"]},{"url":"http://www.securitytracker.com/id/1039978","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://access.redhat.com/errata/RHSA-2018:0998","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://access.redhat.com/errata/RHSA-2018:2185","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://access.redhat.com/errata/RHSA-2018:2186","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://access.redhat.com/errata/RHSA-2018:2187","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://github.com/openssl/openssl/commit/e502cc86df9dafded1694fceb3228ee34d11c11a","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"]},{"url":"https://nodejs.org/en/blog/vulnerability/december-2017-security-releases/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://security.FreeBSD.org/advisories/FreeBSD-SA-17:12.openssl.asc","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://security.gentoo.org/glsa/201712-03","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://security.netapp.com/advisory/ntap-20171208-0001/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst03881en_us","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://www.debian.org/security/2017/dsa-4065","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://www.debian.org/security/2018/dsa-4157","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://www.openssl.org/news/secadv/20171207.txt","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://www.openssl.org/news/secadv/20180327.txt","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"]},{"url":"https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"]},{"url":"https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"]},{"url":"https://www.tenable.com/security/tns-2017-16","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://www.tenable.com/security/tns-2018-04","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://www.tenable.com/security/tns-2018-06","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://www.tenable.com/security/tns-2018-07","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}}]}