CVE-2015-0535Use of a Broken or Risky Cryptographic Algorithm in Dell Bsafe

Severity
7.5HIGHNVD
CNA4.3
EPSS
0.4%
top 36.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 20
Latest updateMay 13

Description

EMC RSA BSAFE Micro Edition Suite (MES) 4.0.x before 4.0.8 and 4.1.x before 4.1.3 and RSA BSAFE SSL-C 2.8.9 and earlier do not properly restrict TLS state transitions, which makes it easier for remote attackers to conduct cipher-downgrade attacks to EXPORT_RSA ciphers via crafted TLS traffic, related to the "FREAK" issue, a similar issue to CVE-2015-0204.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

NVDdell/bsafe4.0.04.0.8+1
NVDdell/bsafe_ssl-c2.8.9

🔴Vulnerability Details

2
GHSA
GHSA-7cgm-fx9j-3rcr: EMC RSA BSAFE Micro Edition Suite (MES) 42022-05-13
CVEList
CVE-2015-0535: EMC RSA BSAFE Micro Edition Suite (MES) 42015-08-20
CVE-2015-0535 — Dell Bsafe vulnerability | cvebase