Observable Timing Discrepancy Vulnerability in Dell BSAFE Crypto-C Micro Edition and Suite
CVE-2020-29506

6.8MEDIUM

Key Information:

Vendor
Dell
Vendor
CVE Published:
11 July 2022

Summary

Dell BSAFE Crypto-C Micro Edition and BSAFE Micro Edition Suite are susceptible to an observable timing discrepancy vulnerability that could allow attackers to infer sensitive data based on the timing of cryptographic operations. This flaw may lead to potential information leakage, impacting the confidentiality and integrity of cryptographic transactions. It is crucial for users to upgrade to the latest versions to mitigate this risk effectively.

Affected Version(s)

Dell BSAFE Crypto-C Micro Edition < 4.1.5 and 4.6

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.