Timing Discrepancy Vulnerability in Dell BSAFE Crypto-C Micro Edition and Suite
CVE-2020-35167

4.8MEDIUM

Key Information:

Vendor
Dell
Vendor
CVE Published:
11 July 2022

Summary

Dell BSAFE Crypto-C Micro Edition prior to version 4.1.5 and Dell BSAFE Micro Edition Suite prior to version 4.6 exhibit an Observable Timing Discrepancy Vulnerability. This flaw can potentially allow attackers to infer sensitive information by analyzing the time taken to respond to certain cryptographic operations. Organizations using these products are advised to update to the latest versions to mitigate the risk posed by this vulnerability.

Affected Version(s)

Dell BSAFE Crypto-C Micro Edition < 4.1.5 or 4.1.4.1

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Physical
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.