Improper input validation in OpenSSL - CVE-2017-3737

 

Improper input validation in OpenSSL - CVE-2017-3737

Published: December 8, 2017 / Updated: February 1, 2018


Vulnerability identifier: #VU9594
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-3737
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information on the target system.

The weakness exists due to an "error state mechanism" when SSL_read() or SSL_write() is called directly after SSL object. A remote attacker can a specially crafted input, trigger a fatal error during a handshake and return it in the initial function call to access or modify sensitive information.

Affected software

OpenSSL
SIMATIC HMI WinCC Flexible
SINUMERIK Integrate Operate Client
SINUMERIK Integrate Access MyMachine service engineer client
SIMATIC WinCC OA
SIMATIC WinCC (TIA Portal)
SIMATIC STEP 7 (TIA Portal)
SIMATIC IPC DiagMonitor
SIMATIC IPC DiagBase
SIMATIC ET 200SP Open Controller
MindConnect Nano (IPC227D)
MindConnect IoT2040
Arch Linux
Debian Linux
Gentoo Linux
Amazon Linux AMI
IBM AIX
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for Power
Red Hat Enterprise Linux Server
FreeBSD
SUSE Linux
Slackware Linux
Ubuntu
Opensuse

SIMATIC S7-1200
LCM8 & LCM16 KVM Switch Firmware
GCM16 & GCM32 KVM Switch Firmware
nodejs-current (Alpine package)
MySQL Server
IBM Cognos Business Intelligence Server
IBM Cognos Analytics
WebSVN
IBM Tivoli Network Manager (ITNM)
QLogic 8Gb Intelligent Pass-thru Module & SAN Switch Module for BladeCenter
QLogic Virtual Fabric Extension Module for IBM BladeCenter
IBM Netezza Performance Server
NetWorker

How to mitigate CVE-2017-3737

Update to version 1.0.2n.

nodejs-current (Alpine package) - addressed in versions 7.2.1-r2, 7.10.1-r1
IBM Cognos Analytics - update to 11.0.13
LCM8 & LCM16 KVM Switch Firmware - update to 1.2.50.00
WebSVN - update to 1.61
GCM16 & GCM32 KVM Switch Firmware - update to 2.4.0.25463
IBM Tivoli Network Manager (ITNM) - addressed in versions 3.9.0.4, 3.9.0.5
QLogic 8Gb Intelligent Pass-thru Module & SAN Switch Module for BladeCenter - update to 7.10.1.46.00
QLogic Virtual Fabric Extension Module for IBM BladeCenter - update to 9.0.3.23.00
IBM Netezza Performance Server - update to 11.2.1.11
NetWorker - update to 19.10.0.0

External References

Related Security Bulletins