Dell BSAFE Crypto-C Micro Edition, version 4.1.5, and Dell BSAFE Micro Edition Suite, versions 4.0 through 4.6.1 and version 5.0, contains an Out-of-bounds Read vulnerability
Published Jul 31, 2024
7.1
HIGHCVSS 3.1
EPSS 0.15%
Description
Dell BSAFE Crypto-C Micro Edition, version 4.1.5, and Dell BSAFE Micro Edition Suite, versions 4.0 through 4.6.1 and version 5.0, contains an Out-of-bounds Read vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Information exposure.
Affected products
-
- Version 4.0StatusaffectedConstraints<=4.1.5
- Version
-
- Version 4.0StatusaffectedConstraints<=4.6.1
- Version 5.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Dell | Dell BSAFE Crypto-C Micro Edition | unaffected |
| |||||||||
| Dell | Dell BSAFE Micro Edition Suite | unaffected |
|
- ≥ 4.0.0 · ≤ 4.1.5
- ≥ 4.0.0 · < 4.6.2
- 5.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
This issue can be mitigated by a workaround, if customer’s implementations are deemed to be vulnerable. Customers with an active maintenance contract can contact BSAFE Support for details about the workaround.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-31799 Advisory
- https://www.dell.com/support/kbdoc/en-us/000212325/dsa-2023-120-dell-bsafe-micro-edition-suite-security-update vendor-advisoryVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-31799 | Advisory | |
| https://www.dell.com/support/kbdoc/en-us/000212325/dsa-2023-120-dell-bsafe-micro-edition-suite-security-update | vendor-advisoryVendor Advisory |
Change history (0)
No recorded changes yet.