CVE-2018-15769

3 documents3 sources
Severity
7.5HIGH
EPSS
1.5%
top 18.99%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 16
Latest updateMay 13

Description

RSA BSAFE Micro Edition Suite versions prior to 4.0.11 (in 4.0.x series) and versions prior to 4.1.6.2 (in 4.1.x series) contain a key management error issue. A malicious TLS server could potentially cause a Denial Of Service (DoS) on TLS clients during the handshake when a very large prime value is sent to the TLS client, and an Ephemeral or Anonymous Diffie-Hellman cipher suite (DHE or ADH) is used.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages12 packages

NVDdell/bsafe4.0.04.0.11+1
NVDoracle/security_service11.1.1.9.0, 12.1.3.0.0, 12.2.1.3.0+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-9jr7-f5xc-87jm: RSA BSAFE Micro Edition Suite versions prior to 42022-05-13
CVEList
CVE-2018-15769: RSA BSAFE Micro Edition Suite versions prior to 42018-11-16