DSA-2024-221: Security Update for Dell BSAFE™ SSL-J Multiple Vulnerabilities
Zusammenfassung: Dell BSAFE SSL-J remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.
Auswirkungen
Medium
Details
|
Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|
CVE-2024-29171 |
Dell BSAFE SSL-J, versions prior to 6.6 and versions 7.0 through 7.2, contains an Improper certificate verification vulnerability. A remote attacker could potentially exploit this vulnerability, leading to information disclosure. |
5.9 |
|
|
CVE-2024-29172 |
Dell BSAFE SSL-J, versions prior to 6.6 and versions 7.0 through 7.2, contains a deadlock vulnerability. A remote attacker could potentially exploit this vulnerability, leading to a Denial of Service. |
5.9 |
|
Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|
CVE-2024-29171 |
Dell BSAFE SSL-J, versions prior to 6.6 and versions 7.0 through 7.2, contains an Improper certificate verification vulnerability. A remote attacker could potentially exploit this vulnerability, leading to information disclosure. |
5.9 |
|
|
CVE-2024-29172 |
Dell BSAFE SSL-J, versions prior to 6.6 and versions 7.0 through 7.2, contains a deadlock vulnerability. A remote attacker could potentially exploit this vulnerability, leading to a Denial of Service. |
5.9 |
Betroffene Produkte und Korrektur
| CVEs Addressed | Product | Affected Versions | Remediated Versions | Link |
|---|---|---|---|---|
| CVE-2024-29171, CVE-2024-29172 | Dell BSAFE SSL-J | Versions prior to 6.6 | Version 6.6 | How To Request a Dell BSAFE product download |
| CVE-2024-29171, CVE-2024-29172 | Dell BSAFE SSL-J | Versions 7.0 through 7.2 | Version 7.2.1 | How To Request a Dell BSAFE product download |
| CVEs Addressed | Product | Affected Versions | Remediated Versions | Link |
|---|---|---|---|---|
| CVE-2024-29171, CVE-2024-29172 | Dell BSAFE SSL-J | Versions prior to 6.6 | Version 6.6 | How To Request a Dell BSAFE product download |
| CVE-2024-29171, CVE-2024-29172 | Dell BSAFE SSL-J | Versions 7.0 through 7.2 | Version 7.2.1 | How To Request a Dell BSAFE product download |
These issues may be mitigated by a workaround, if the customer’s implementations are deemed vulnerable. Customers with an active maintenance contract can contact BSAFE Support for details about the workarounds.
Revisionsverlauf
| Revision | Date | Description |
|---|---|---|
| 1.0 | 2024-07-02 | Initial Release |
| 2.0 | 2024-07-31 | Formatting changes only. No changes to content. |
| 3.0 | 2025-02-11 | Public disclosure of CVE details. |
| 4.0 | 2025-02-12 | Added version numbers to CVE descriptions and updated the versions in the affected product list. |