CVE-2023-28074

Dell BSAFE Crypto-C Micro Edition, version 4.1.5, and Dell BSAFE Micro Edition Suite, versions 4.0 through 4.6.1 and version 5.0, contains an Out-of-bounds Read vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Information exposure.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:dell:bsafe_crypto-c-micro-edition:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:bsafe_micro-edition-suite:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:bsafe_micro-edition-suite:5.0:*:*:*:*:*:*:*

History

20 Aug 2024, 17:15

Type Values Removed Values Added
Summary (en) Dell BSAFE Crypto-C Micro Edition 4.1.5 and Dell BSAFE Micro Edition Suite, versions 4.0 through 4.6.1 and version 5.0 contain a buffer over-read vulnerability. (en) Dell BSAFE Crypto-C Micro Edition, version 4.1.5, and Dell BSAFE Micro Edition Suite, versions 4.0 through 4.6.1 and version 5.0, contains an Out-of-bounds Read vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Information exposure.
CWE CWE-190

08 Aug 2024, 21:14

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 6.2
v2 : unknown
v3 : 7.1
References () https://www.dell.com/support/kbdoc/en-us/000212325/dsa-2023-120-dell-bsafe-micro-edition-suite-security-update - () https://www.dell.com/support/kbdoc/en-us/000212325/dsa-2023-120-dell-bsafe-micro-edition-suite-security-update - Vendor Advisory
CWE CWE-125
First Time Dell bsafe Micro-edition-suite
Dell bsafe Crypto-c-micro-edition
Dell
CPE cpe:2.3:a:dell:bsafe_crypto-c-micro-edition:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:bsafe_micro-edition-suite:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:bsafe_micro-edition-suite:5.0:*:*:*:*:*:*:*

31 Jul 2024, 12:57

Type Values Removed Values Added
Summary
  • (es) Dell BSAFE Crypto-C Micro Edition 4.1.5 y Dell BSAFE Micro Edition Suite, versiones 4.0 a 4.6.1 y versión 5.0 contienen una vulnerabilidad de sobrelectura de búfer.

31 Jul 2024, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-31 08:15

Updated : 2024-08-20 17:15


NVD link : CVE-2023-28074

Mitre link : CVE-2023-28074

CVE.ORG link : CVE-2023-28074


JSON object : View

Products Affected

dell

  • bsafe_micro-edition-suite
  • bsafe_crypto-c-micro-edition
CWE
CWE-125

Out-of-bounds Read