#VU79014 Unchecked Return Value in RSA BSAFE Micro Edition Suite - CVE-2020-5359


Vulnerability identifier: #VU79014

Vulnerability risk: Medium

CVSSv4.0: 2.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2020-5359

CWE-ID: CWE-252

Exploitation vector: Network

Exploit availability: No

Vulnerable software:
RSA BSAFE Micro Edition Suite
Client/Desktop applications / Other client software

Vendor: Dell

Description

The vulnerability allows a remote attacker to modify and corrupt the encrypted data.

The vulnerability exists due to unchecked return value. A remote unauthenticated attacker can trigger the vulnerability to modify and corrupt the encrypted data on the target system.

Mitigation
Install updates from vendor's website.

Vulnerable software versions

RSA BSAFE Micro Edition Suite: before 4.5


External links
https://www.dell.com/support/kbdoc/en-us/000181098/dsa-2020-114-dell-bsafe-micro-edition-suite-multiple-security-vulnerabilities
https://www.oracle.com/security-alerts/cpuApr2021.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability