CVE-2015-0536Dell Bsafe vulnerability

3 documents3 sources
Severity
7.5HIGHNVD
EPSS
1.0%
top 22.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 20
Latest updateMay 13

Description

EMC RSA BSAFE Micro Edition Suite (MES) 4.0.x before 4.0.8 and 4.1.x before 4.1.3 and RSA BSAFE SSL-C 2.8.9 and earlier, when client authentication and an ephemeral Diffie-Hellman ciphersuite are enabled, allow remote attackers to cause a denial of service (daemon crash) via a ClientKeyExchange message with a length of zero, a similar issue to CVE-2015-1787.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

NVDdell/bsafe4.0.04.0.8+1
NVDdell/bsafe_ssl-c2.8.9

🔴Vulnerability Details

2
GHSA
GHSA-8x5r-qq77-fp3r: EMC RSA BSAFE Micro Edition Suite (MES) 42022-05-13
CVEList
CVE-2015-0536: EMC RSA BSAFE Micro Edition Suite (MES) 42015-08-20