Heap Inspection Vulnerability in RSA BSAFE Crypto-C Micro Edition
CVE-2019-3733
4.4MEDIUM
Key Information:
- Vendor
- Dell
- Vendor
- CVE Published:
- 30 September 2019
Summary
The RSA BSAFE Crypto-C Micro Edition software, prior to version 4.1.4, is affected by a vulnerability that stems from improper clearing of heap memory before it is released. This flaw can allow a malicious remote user to exploit the heap inspection vulnerability, potentially leading to unauthorized access to sensitive data. Users of affected versions should consider upgrading to the latest version to mitigate any risk of information exposure. For more details, visit Dell's support page.
Affected Version(s)
RSA BSAFE Crypto-C Micro Edition < 4.1.4
RSA BSAFE MES < 4.4
References
CVSS V3.1
Score:
4.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved