Unmaintained Third-Party Component Vulnerability in Dell BSAFE SSL-J and Crypto-J
CVE-2022-34381
9.1CRITICAL
Key Information:
- Vendor
- Dell
- Vendor
- CVE Published:
- 2 February 2024
Summary
An unmaintained third-party component found in Dell BSAFE SSL-J versions 7.0 and previous versions up to 6.5, alongside Dell BSAFE Crypto-J versions earlier than 6.2.6.1, poses a significant security vulnerability. This flaw allows an unauthenticated remote attacker the potential to exploit the vulnerability, which can lead to serious compromise of affected systems. Users of these products are strongly recommended to upgrade to the secure versions to mitigate associated risks. For more details on the remediation, refer to Dell's security advisory.
Affected Version(s)
Dell BSAFE Crypto-J 0 < 6.2.6.1
Dell BSAFE SSL-J 7.0
Dell BSAFE SSL-J 0 < 6.5
References
CVSS V3.1
Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved