Dell BSAFE SSL-J version 7.0 and all versions prior to 6.5, and Dell BSAFE Crypto-J versions prior to 6.2.6.1 contain an unmaintained third-party component vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to the compromise of the impacted system. This is a Critical vulnerability and Dell recommends customers to upgrade at the earliest opportunity.
The vulnerability results from the presence of an outdated third-party component in the product that is no longer maintained by its vendor and contains unpatched security flaws (CWE-1329). The attacker does not need to possess any credentials or user interaction — the attack can be conducted remotely over the network. The detailed exploitation mechanism has not been disclosed in the public description.
Successful exploitation of the vulnerability may lead to complete takeover of system control, including breach of data confidentiality and integrity. System availability is not directly indicated as threatened, however system compromise may have far-reaching consequences for the security of the entire environment.
Dell recommends updating to the following versions as soon as possible: Dell BSAFE SSL-J 6.5 or 7.1 and Dell BSAFE Crypto-J 6.2.6.1 or 7.0. Detailed information is available in the vendor's security bulletin DSA-2022-208 at the address indicated in the references.
Dell BSAFE SSL-J version 7.0 and all versions earlier than 6.5; Dell BSAFE Crypto-J all versions earlier than 6.2.6.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NDell Bsafe Crypto J
APPDell< 6.2.6.1Dell Bsafe Ssl J
APPDell7.0< 6.5
Related vulnerabilities
An issue was discovered in EMC RSA BSAFE Crypto-J versions prior to 6.2.2. There is an Improper OCSP Validatio...
EMC RSA BSAFE Micro Edition Suite (MES) 4.0.x before 4.0.8 and 4.1.x before 4.1.3, RSA BSAFE Crypto-J before 6...
The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers ...
RSA BSAFE SSL-J 3.0, 3.0.1 and 3.1, as used in Cisco iCND 2.0, caches session IDs from failed login attempts, ...
Dell BSAFE Crypto-J generates an error message that includes sensitive information about its environment and a...