Risk | Medium |
Patch available | YES |
Number of vulnerabilities | 1 |
CVE-ID | CVE-2019-3733 |
CWE-ID | CWE-244 |
Exploitation vector | Network |
Public exploit | N/A |
Vulnerable software Subscribe |
RSA BSAFE Crypto-C Server applications / Encryption software |
Vendor | Dell |
Security Bulletin
This security bulletin contains one medium risk vulnerability.
EUVDB-ID: #VU21463
Risk: Medium
CVSSv3.1: 4.3 [CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C]
CVE-ID: CVE-2019-3733
CWE-ID:
CWE-244 - Improper Clearing of Heap Memory Before Release ('Heap Inspection')
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to using realloc() to resize buffers that store sensitive information can leave the sensitive information exposed to attack, because it is not removed from memory. A remote authenticated attacker can extract information leaving data at risk of exposure.Install updates from vendor's website.
Vulnerable software versionsRSA BSAFE Crypto-C: before 4.1.4
External linksQ & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.