Observable Timing Discrepancy in Dell BSAFE Crypto-C Micro Edition and Micro Edition Suite
CVE-2020-35166

9.8CRITICAL

Key Information:

Vendor
Dell
Vendor
CVE Published:
11 July 2022

Summary

The Dell BSAFE Crypto-C Micro Edition and the Dell BSAFE Micro Edition Suite are vulnerable due to observable timing discrepancies, which may allow an attacker to gain information about sensitive data. This vulnerability affects versions before 4.1.5 of the Crypto-C Micro Edition and versions prior to 4.6 of the Micro Edition Suite, potentially enabling unauthorized access or manipulation of cryptographic processes.

Affected Version(s)

BSAFE Crypto-C Micro Edition 0 < 4.1.5

Dell BSAFE Micro Edition Suite 0 < 4.6

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.