CRITICAL🇵🇱 Wersja polska

CVE-2022-34381

CVSS 9.1v3.1pub. 2024-02-02upd. 2024-11-21

Dell BSAFE SSL-J version 7.0 and all versions prior to 6.5, and Dell BSAFE Crypto-J versions prior to 6.2.6.1 contain an unmaintained third-party component vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to the compromise of the impacted system. This is a Critical vulnerability and Dell recommends customers to upgrade at the earliest opportunity.

🤖 AI Analysis
How it works

The vulnerability results from the presence of an outdated third-party component in the product that is no longer maintained by its vendor and contains unpatched security flaws (CWE-1329). The attacker does not need to possess any credentials or user interaction — the attack can be conducted remotely over the network. The detailed exploitation mechanism has not been disclosed in the public description.

Impact

Successful exploitation of the vulnerability may lead to complete takeover of system control, including breach of data confidentiality and integrity. System availability is not directly indicated as threatened, however system compromise may have far-reaching consequences for the security of the entire environment.

Mitigation & patch

Dell recommends updating to the following versions as soon as possible: Dell BSAFE SSL-J 6.5 or 7.1 and Dell BSAFE Crypto-J 6.2.6.1 or 7.0. Detailed information is available in the vendor's security bulletin DSA-2022-208 at the address indicated in the references.

Who is affected

Dell BSAFE SSL-J version 7.0 and all versions earlier than 6.5; Dell BSAFE Crypto-J all versions earlier than 6.2.6.1

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Dell Bsafe Crypto J

    APP
    Dell
    < 6.2.6.1
  • Dell Bsafe Ssl J

    APP
    Dell
    7.0< 6.5
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2016-8212HIGH7.5same product

An issue was discovered in EMC RSA BSAFE Crypto-J versions prior to 6.2.2. There is an Improper OCSP Validatio...

CVE-2015-0534HIGH7.5same product

EMC RSA BSAFE Micro Edition Suite (MES) 4.0.x before 4.0.8 and 4.1.x before 4.1.3, RSA BSAFE Crypto-J before 6...

CVE-2004-0079HIGH7.5same product

The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers ...

CVE-2001-1105HIGH7.5same product

RSA BSAFE SSL-J 3.0, 3.0.1 and 3.1, as used in Cisco iCND 2.0, caches session IDs from failed login attempts, ...

CVE-2025-26333MEDIUM5.9same product

Dell BSAFE Crypto-J generates an error message that includes sensitive information about its environment and a...