CVE-2020-35168

CWE-3116 documents4 sources
Severity
9.8CRITICAL
EPSS
0.1%
top 65.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 11
Latest updateApr 15

Description

Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timing Discrepancy Vulnerability.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.0 | Impact: 3.6

Affected Packages7 packages

CVEListV5dell/dell_bsafe_crypto-c_micro_editionunspecified4.1.5, 4.6
NVDoracle/database12.1.0.2, 19c, 21c+2
NVDoracle/weblogic12.2.1.3.0, 12.2.1.4.0+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-66xw-cm7f-gxw3: Dell BSAFE Crypto-C Micro Edition, versions before 42022-07-12
CVEList
CVE-2020-35168: Dell BSAFE Crypto-C Micro Edition, versions before 42022-07-11

📋Vendor Advisories

3
Oracle
Oracle Oracle Systems Risk Matrix: Application Server (Dell BSAFE Micro Edition Suite) — CVE-2020-351682024-04-15
Oracle
Oracle Oracle TimesTen In-Memory Database Risk Matrix: TimesTen IMDB (Dell BSAFE Micro Edition Suite) — CVE-2020-351682023-07-15
Oracle
Oracle Oracle Communications Applications Risk Matrix: Other (Dell BSAFE Micro Edition Suite) — CVE-2020-351682023-04-15