Dell BSAFE Crypto-C Micro Edition, version 4.1.5, and Dell BSAFE Micro Edition Suite, versions 4.0 through 4.6.1 and version 5.0, contains an Out-of-bounds Read vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Information exposure.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-31799 Dell BSAFE Crypto-C Micro Edition, version 4.1.5, and Dell BSAFE Micro Edition Suite, versions 4.0 through 4.6.1 and version 5.0, contains an Out-of-bounds Read vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Information exposure.
Fixes

Solution

No solution given by the vendor.


Workaround

This issue can be mitigated by a workaround, if customer’s implementations are deemed to be vulnerable. Customers with an active maintenance contract can contact BSAFE Support for details about the workaround.

History

Tue, 20 Aug 2024 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-190

Tue, 20 Aug 2024 16:45:00 +0000

Type Values Removed Values Added
Description Dell BSAFE Crypto-C Micro Edition 4.1.5 and Dell BSAFE Micro Edition Suite, versions 4.0 through 4.6.1 and version 5.0 contain a buffer over-read vulnerability. Dell BSAFE Crypto-C Micro Edition, version 4.1.5, and Dell BSAFE Micro Edition Suite, versions 4.0 through 4.6.1 and version 5.0, contains an Out-of-bounds Read vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Information exposure.

Thu, 08 Aug 2024 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell bsafe Crypto-c-micro-edition
Dell bsafe Micro-edition-suite
Weaknesses CWE-125
CPEs cpe:2.3:a:dell:bsafe_crypto-c-micro-edition:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:bsafe_micro-edition-suite:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:bsafe_micro-edition-suite:5.0:*:*:*:*:*:*:*
Vendors & Products Dell
Dell bsafe Crypto-c-micro-edition
Dell bsafe Micro-edition-suite

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2024-08-20T16:31:10.234Z

Reserved: 2023-03-10T05:07:55.140Z

Link: CVE-2023-28074

cve-icon Vulnrichment

Updated: 2024-08-01T17:46:02.992Z

cve-icon NVD

Status : Modified

Published: 2024-07-31T08:15:02.243

Modified: 2024-08-20T17:15:10.200

Link: CVE-2023-28074

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.