CVE-2018-0732

HIGHCVSS 7.5/10EPSS 49.27%

Last modified

CVE-2018-0732 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. During key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server can send a very large prime value to the client. This will cause the client to spend an unreasonably long period of time generating a key for this prime resulting in a hang until the client has finished. EPSS estimates a 49.27% chance of exploitation in the next 30 days.

Description

During key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server can send a very large prime value to the client. This will cause the client to spend an unreasonably long period of time generating a key for this prime resulting in a hang until the client has finished. This could be exploited in a Denial Of Service attack. Fixed in OpenSSL 1.1.0i-dev (Affected 1.1.0-1.1.0h). Fixed in OpenSSL 1.0.2p-dev (Affected 1.0.2-1.0.2o).

Metrics

CVSS 3.1
7.5/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Probability
49.27%

98.7th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
OpensslOpenssl>= 1.0.2, <= 1.0.2o
OpensslOpenssl>= 1.1.0, <= 1.1.0h
CanonicalUbuntu Linux12.04
CanonicalUbuntu Linux14.04
CanonicalUbuntu Linux16.04
CanonicalUbuntu Linux17.10
CanonicalUbuntu Linux18.04
DebianDebian Linux8.0
NodejsNode.Js>= 6.0.0, < 6.8.1
NodejsNode.Js>= 6.9.0, < 6.14.4
NodejsNode.Js>= 8.0.0, < 8.8.1
NodejsNode.Js>= 8.9.0, < 8.11.4
NodejsNode.Js>= 10.0.0, < 10.9.0

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2018-0732?
During key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server can send a very large prime value to the client. This will cause the client to spend an unreasonably long period of time generating a key for this prime resulting in a hang until the client has finished. This could be exploited in a Denial Of Service attack. Fixed in OpenSSL 1.1.0i-dev (Affected 1.1.0-1.1.0h). Fixed in OpenSSL 1.0.2p-dev (Affected 1.0.2-1.0.2o).
How severe is CVE-2018-0732?
CVE-2018-0732 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 49.27% probability of exploitation in the next 30 days.
How do I fix CVE-2018-0732?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2018-0732?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST