Vulnerability identifier: #VU79014
Vulnerability risk: Medium
CVSSv4.0: 2.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID:
CWE-ID:
CWE-252
Exploitation vector: Network
Exploit availability: No
Vulnerable software:
RSA BSAFE Micro Edition Suite
Client/Desktop applications /
Other client software
Vendor: Dell
Description
The vulnerability allows a remote attacker to modify and corrupt the encrypted data.
The vulnerability exists due to unchecked return value. A remote unauthenticated attacker can trigger the vulnerability to modify and corrupt the encrypted data on the target system.
Mitigation
Install updates from vendor's website.
Vulnerable software versions
RSA BSAFE Micro Edition Suite: before 4.5
External links
https://www.dell.com/support/kbdoc/en-us/000181098/dsa-2020-114-dell-bsafe-micro-edition-suite-multiple-security-vulnerabilities
https://www.oracle.com/security-alerts/cpuApr2021.html
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.