CVE-2017-3733: HP Operations Agent
High severity, CVSS 7.5. EPSS: 12.9% chance of exploitation in the next 30 days.
During a renegotiation handshake if the Encrypt-Then-Mac extension is negotiated where it was not in the original handshake (or vice-versa) then this can cause OpenSSL 1.1.0 before 1.1.0e to crash (dependent on ciphersuite). Both clients and servers are affected.
Affected products
- HP Operations Agent: version 11.14 only; version 11.15 only
- OpenSSL OpenSSL: version 1.1.0 only; version 1.1.0a only; version 1.1.0b only; version 1.1.0c only; version 1.1.0d only
Published 2017-05-04. Last modified 2026-06-17.