Improper input validation in OpenSSL - CVE-2017-3737
Published: December 8, 2017 / Updated: February 1, 2018
Vulnerability identifier: #VU9594
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-3737
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information on the target system.
The weakness exists due to an "error state mechanism" when SSL_read() or SSL_write() is called directly after SSL object. A remote attacker can a specially crafted input, trigger a fatal error during a handshake and return it in the initial function call to access or modify sensitive information.
The weakness exists due to an "error state mechanism" when SSL_read() or SSL_write() is called directly after SSL object. A remote attacker can a specially crafted input, trigger a fatal error during a handshake and return it in the initial function call to access or modify sensitive information.
Affected software
OpenSSL
SIMATIC HMI WinCC Flexible
SINUMERIK Integrate Operate Client
SINUMERIK Integrate Access MyMachine service engineer client
SIMATIC WinCC OA
SIMATIC WinCC (TIA Portal)
SIMATIC STEP 7 (TIA Portal)
SIMATIC IPC DiagMonitor
SIMATIC IPC DiagBase
SIMATIC ET 200SP Open Controller
MindConnect Nano (IPC227D)
MindConnect IoT2040
Arch Linux
Debian Linux
Gentoo Linux
Amazon Linux AMI
IBM AIX
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for Power
Red Hat Enterprise Linux Server
FreeBSD
SUSE Linux
Slackware Linux
Ubuntu
Opensuse
SIMATIC S7-1200
LCM8 & LCM16 KVM Switch Firmware
GCM16 & GCM32 KVM Switch Firmware
nodejs-current (Alpine package)
MySQL Server
IBM Cognos Business Intelligence Server
IBM Cognos Analytics
WebSVN
IBM Tivoli Network Manager (ITNM)
QLogic 8Gb Intelligent Pass-thru Module & SAN Switch Module for BladeCenter
QLogic Virtual Fabric Extension Module for IBM BladeCenter
IBM Netezza Performance Server
NetWorker
SIMATIC HMI WinCC Flexible
SINUMERIK Integrate Operate Client
SINUMERIK Integrate Access MyMachine service engineer client
SIMATIC WinCC OA
SIMATIC WinCC (TIA Portal)
SIMATIC STEP 7 (TIA Portal)
SIMATIC IPC DiagMonitor
SIMATIC IPC DiagBase
SIMATIC ET 200SP Open Controller
MindConnect Nano (IPC227D)
MindConnect IoT2040
Arch Linux
Debian Linux
Gentoo Linux
Amazon Linux AMI
IBM AIX
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for Power
Red Hat Enterprise Linux Server
FreeBSD
SUSE Linux
Slackware Linux
Ubuntu
Opensuse
SIMATIC S7-1200
LCM8 & LCM16 KVM Switch Firmware
GCM16 & GCM32 KVM Switch Firmware
nodejs-current (Alpine package)
MySQL Server
IBM Cognos Business Intelligence Server
IBM Cognos Analytics
WebSVN
IBM Tivoli Network Manager (ITNM)
QLogic 8Gb Intelligent Pass-thru Module & SAN Switch Module for BladeCenter
QLogic Virtual Fabric Extension Module for IBM BladeCenter
IBM Netezza Performance Server
NetWorker
How to mitigate CVE-2017-3737
Update to version 1.0.2n.
nodejs-current (Alpine package) - addressed in versions 7.2.1-r2, 7.10.1-r1
IBM Cognos Analytics - update to 11.0.13
LCM8 & LCM16 KVM Switch Firmware - update to 1.2.50.00
WebSVN - update to 1.61
GCM16 & GCM32 KVM Switch Firmware - update to 2.4.0.25463
IBM Tivoli Network Manager (ITNM) - addressed in versions 3.9.0.4, 3.9.0.5
QLogic 8Gb Intelligent Pass-thru Module & SAN Switch Module for BladeCenter - update to 7.10.1.46.00
QLogic Virtual Fabric Extension Module for IBM BladeCenter - update to 9.0.3.23.00
IBM Netezza Performance Server - update to 11.2.1.11
NetWorker - update to 19.10.0.0
IBM Cognos Analytics - update to 11.0.13
LCM8 & LCM16 KVM Switch Firmware - update to 1.2.50.00
WebSVN - update to 1.61
GCM16 & GCM32 KVM Switch Firmware - update to 2.4.0.25463
IBM Tivoli Network Manager (ITNM) - addressed in versions 3.9.0.4, 3.9.0.5
QLogic 8Gb Intelligent Pass-thru Module & SAN Switch Module for BladeCenter - update to 7.10.1.46.00
QLogic Virtual Fabric Extension Module for IBM BladeCenter - update to 9.0.3.23.00
IBM Netezza Performance Server - update to 11.2.1.11
NetWorker - update to 19.10.0.0
External References
Related Security Bulletins
- Multiple vulnerabilities in OpenSSL
- Slackware Linux update for openssl
- FreeBSD update for OpenSSL
- Ubuntu update for OpenSSL
- Gentoo update for OpenSSL
- Debian update for openssl1.0
- Arch Linux update for lib32-openssl-1.0
- Multiple vulnerabilities in Oracle MySQL Server
- Security restrictions bypass in IBM AIX
- OpenSUSE Linux update for mysql-community-server
- Red Hat update for openssl
- OpenSUSE Linux update for virtualbox
- Amazon Linux AMI update for openssl
- OpenSUSE Linux update for openssl
- SUSE Linux update for openssl
- Multiple vulnerabilities in IBM Cognos Business Intelligence Server
- Information disclosure in Siemens Industrial Products
- Multiple vulnerabilities in IBM Cognos Analytics
- Improper input validation in nodejs-current (Alpine package)
- Multiple vulnerabilities in IBM Tivoli Network Manager IP Edition
- Multiple vulnerabilities in QLogic 8Gb Intelligent Pass-thru Module and SAN Switch Module for IBM BladeCenter and QLogic Virtual Fabric Extension Module for IBM BladeCenter
- Multiple vulnerabilities in Dell Networker
- Multiple vulnerabilities in IBM Netezza Performance Server
- Multiple vulnerabilities in IBM GCM16 & GCM32 and LCM8 & LCM16 KVM Switch Firmware