Observable Timing Discrepancy in Dell BSAFE Crypto-C Micro Edition
CVE-2020-35164

6.7MEDIUM

Key Information:

Vendor
Dell
Vendor
CVE Published:
11 July 2022

Summary

Dell BSAFE Crypto-C Micro Edition versions prior to 4.1.5 and BSAFE Micro Edition Suite versions prior to 4.6 contain a vulnerability that manifests as an observable timing discrepancy. This flaw can potentially be exploited by attackers to gain insights into sensitive information or cryptographic operations, thereby compromising the security integrity of the affected systems. It is vital for organizations using these products to update to the patched versions to mitigate any security risks.

Affected Version(s)

Dell BSAFE Crypto-C Micro Edition < 4.1.5 and 4.6

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.