CVE-2022-24409Covert Timing Channel in Dell Bsafe Ssl-j

Severity
7.5HIGHNVD
CNA5.9
EPSS
0.7%
top 26.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 23
Latest updateJul 15

Description

Dell BSAFE SSL-J contains remediation for a covert timing channel vulnerability that may be exploited by malicious users to compromise the affected system. Only customers with active BSAFE maintenance contracts can receive details about this vulnerability. Public disclosure of the vulnerability details will be shared at a later date.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.6 | Impact: 5.9

Affected Packages2 packages

NVDdell/bsafe_ssl-j6.1.06.4
CVEListV5dell/dell_bsafe_ssl-j5.1unspecified+1

🔴Vulnerability Details

2
GHSA
GHSA-qrhr-42fp-q7c4: Only customers with active BSAFE maintenance contracts can receive details about this vulnerability2022-02-24
CVEList
CVE-2022-24409: Dell BSAFE SSL-J contains remediation for a covert timing channel vulnerability that may be exploited by malicious users to compromise the affected sy2022-02-23

📋Vendor Advisories

1
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Centralized Thirdparty Jars (BSAFE SSL-J) — CVE-2022-244092023-07-15
CVE-2022-24409 — Covert Timing Channel in Dell | cvebase