PT-2018-3428 · Rsa · Emc Rsa Bsafe Micro Edition Suite

Publicado

2018-11-16

·

Atualizado

2022-04-18

·

CVE-2018-15769

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: RSA BSAFE Micro Edition Suite versions prior to 4.0.11 RSA BSAFE Micro Edition Suite versions prior to 4.1.6.2
Description: The issue is related to errors in managing cryptographic keys. It may allow a remote attacker to cause a denial of service. A malicious TLS server could potentially cause this issue on TLS clients during the handshake when a very large prime value is sent to the TLS client, and an Ephemeral or Anonymous Diffie-Hellman cipher suite (DHE or ADH) is used.
Recommendations: For RSA BSAFE Micro Edition Suite versions prior to 4.0.11, update to version 4.0.11 or later. For RSA BSAFE Micro Edition Suite versions prior to 4.1.6.2, update to version 4.1.6.2 or later.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2020-01103
CVE-2018-15769

Produtos afetados

Emc Rsa Bsafe Micro Edition Suite