Observable Timing Discrepancy in Dell BSAFE Crypto-C Micro Edition and Micro Edition Suite
CVE-2020-35166
9.8CRITICAL
Key Information:
- Vendor
- Dell
- Vendor
- CVE Published:
- 11 July 2022
Summary
The Dell BSAFE Crypto-C Micro Edition and the Dell BSAFE Micro Edition Suite are vulnerable due to observable timing discrepancies, which may allow an attacker to gain information about sensitive data. This vulnerability affects versions before 4.1.5 of the Crypto-C Micro Edition and versions prior to 4.6 of the Micro Edition Suite, potentially enabling unauthorized access or manipulation of cryptographic processes.
Affected Version(s)
BSAFE Crypto-C Micro Edition 0 < 4.1.5
Dell BSAFE Micro Edition Suite 0 < 4.6
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved