CVE-2022-34381

Dell BSAFE SSL-J version 7.0 and all versions prior to 6.5, and Dell BSAFE Crypto-J versions prior to 6.2.6.1 contain an unmaintained third-party component vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to the compromise of the impacted system. This is a Critical vulnerability and Dell recommends customers to upgrade at the earliest opportunity.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:dell:bsafe_ssl-j:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:bsafe_ssl-j:7.0:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:dell:bsafe_crypto-j:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:09

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : 9.1
References () https://www.dell.com/support/kbdoc/en-us/000203278/dsa-2022-208-dell-bsafe-ssl-j-6-5-and-7-1-and-dell-bsafe-crypto-j-6-2-6-1-and-7-0-security-vulnerability - Vendor Advisory () https://www.dell.com/support/kbdoc/en-us/000203278/dsa-2022-208-dell-bsafe-ssl-j-6-5-and-7-1-and-dell-bsafe-crypto-j-6-2-6-1-and-7-0-security-vulnerability - Vendor Advisory

09 Feb 2024, 19:16

Type Values Removed Values Added
CPE cpe:2.3:a:dell:bsafe_ssl-j:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:bsafe_ssl-j:7.0:*:*:*:*:*:*:*
cpe:2.3:a:dell:bsafe_crypto-j:*:*:*:*:*:*:*:*
First Time Dell
Dell bsafe Crypto-j
Dell bsafe Ssl-j
References () https://www.dell.com/support/kbdoc/en-us/000203278/dsa-2022-208-dell-bsafe-ssl-j-6-5-and-7-1-and-dell-bsafe-crypto-j-6-2-6-1-and-7-0-security-vulnerability - () https://www.dell.com/support/kbdoc/en-us/000203278/dsa-2022-208-dell-bsafe-ssl-j-6-5-and-7-1-and-dell-bsafe-crypto-j-6-2-6-1-and-7-0-security-vulnerability - Vendor Advisory
CWE NVD-CWE-Other
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

02 Feb 2024, 16:30

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-02 16:15

Updated : 2024-11-21 07:09


NVD link : CVE-2022-34381

Mitre link : CVE-2022-34381

CVE.ORG link : CVE-2022-34381


JSON object : View

Products Affected

dell

  • bsafe_ssl-j
  • bsafe_crypto-j
CWE
CWE-1329

Reliance on Component That is Not Updateable

NVD-CWE-Other