PT-2022-8920 · Dell · Dell Bsafe Crypto-C Micro Edition+1

Published

2022-07-11

·

Updated

2022-10-06

·

CVE-2020-35167

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell BSAFE Crypto-C Micro Edition versions prior to 4.1.5 Dell BSAFE Micro Edition Suite versions prior to 4.6
Description The issue is related to an Observable Timing Discrepancy. This means that the time it takes for the software to respond to different inputs can be measured and used to deduce sensitive information.
Recommendations For Dell BSAFE Crypto-C Micro Edition versions prior to 4.1.5, update to version 4.1.5 or later. For Dell BSAFE Micro Edition Suite versions prior to 4.6, update to version 4.6 or later.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2020-35167

Affected Products

Dell Bsafe Crypto-C Micro Edition
Dell Bsafe Micro Edition Suite