Observable Timing Discrepancy in Dell BSAFE Crypto-C Micro Edition
CVE-2020-35164
6.7MEDIUM
Summary
Dell BSAFE Crypto-C Micro Edition versions prior to 4.1.5 and BSAFE Micro Edition Suite versions prior to 4.6 contain a vulnerability that manifests as an observable timing discrepancy. This flaw can potentially be exploited by attackers to gain insights into sensitive information or cryptographic operations, thereby compromising the security integrity of the affected systems. It is vital for organizations using these products to update to the patched versions to mitigate any security risks.
Affected Version(s)
Dell BSAFE Crypto-C Micro Edition < 4.1.5 and 4.6
References
CVSS V3.1
Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved