CVE-2020-35167Sensitive Information Exposure in Dell Bsafe Crypto-c Micro Edition

Severity
9.8CRITICALNVD
CNA4.8
EPSS
0.7%
top 27.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 11
Latest updateJul 12

Description

Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timing Discrepancy Vulnerability.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages7 packages

CVEListV5dell/dell_bsafe_crypto-c_micro_editionunspecified4.1.5 or 4.1.4.1
NVDoracle/database12.1.0.2, 19c, 21c+2
NVDoracle/weblogic12.2.1.3.0, 12.2.1.4.0+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-x72h-w2cq-3vhh: Dell BSAFE Crypto-C Micro Edition, versions before 42022-07-12
CVEList
CVE-2020-35167: Dell BSAFE Crypto-C Micro Edition, versions before 42022-07-11
CVE-2020-35167 — Sensitive Information Exposure in Dell | cvebase