DSA-2024-221: Security Update for Dell BSAFE™ SSL-J Multiple Vulnerabilities

Zusammenfassung: Dell BSAFE SSL-J remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.

Dieser Artikel gilt für Dieser Artikel gilt nicht für Dieser Artikel ist nicht an ein bestimmtes Produkt gebunden. In diesem Artikel werden nicht alle Produktversionen aufgeführt.

Auswirkungen

Medium

Details

Proprietary Code CVEs

Description

CVSS Base Score

CVSS Vector String

CVE-2024-29171

Dell BSAFE SSL-J, versions prior to 6.6 and versions 7.0 through 7.2, contains an Improper certificate verification vulnerability. A remote attacker could potentially exploit this vulnerability, leading to information disclosure.

5.9

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NThis hyperlink is taking you to a website outside of Dell Technologies.

CVE-2024-29172

Dell BSAFE SSL-J, versions prior to 6.6 and versions 7.0 through 7.2, contains a deadlock vulnerability. A remote attacker could potentially exploit this vulnerability, leading to a Denial of Service.

5.9

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HThis hyperlink is taking you to a website outside of Dell Technologies.

Proprietary Code CVEs

Description

CVSS Base Score

CVSS Vector String

CVE-2024-29171

Dell BSAFE SSL-J, versions prior to 6.6 and versions 7.0 through 7.2, contains an Improper certificate verification vulnerability. A remote attacker could potentially exploit this vulnerability, leading to information disclosure.

5.9

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NThis hyperlink is taking you to a website outside of Dell Technologies.

CVE-2024-29172

Dell BSAFE SSL-J, versions prior to 6.6 and versions 7.0 through 7.2, contains a deadlock vulnerability. A remote attacker could potentially exploit this vulnerability, leading to a Denial of Service.

5.9

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HThis hyperlink is taking you to a website outside of Dell Technologies.

Dell Technologies empfiehlt allen Kunden, sowohl die CVSS-Gesamtbewertung als auch alle relevanten zeitlichen und umweltbezogenen Bewertungen zu berücksichtigen, die sich auf den potenziellen Schweregrad einer bestimmten Sicherheitsschwachstelle auswirken können.

Betroffene Produkte und Korrektur

CVEs Addressed Product Affected Versions Remediated Versions Link
CVE-2024-29171, CVE-2024-29172 Dell BSAFE SSL-J Versions prior to 6.6 Version 6.6 How To Request a Dell BSAFE product download
CVE-2024-29171, CVE-2024-29172 Dell BSAFE SSL-J Versions 7.0 through 7.2 Version 7.2.1 How To Request a Dell BSAFE product download


 

CVEs Addressed Product Affected Versions Remediated Versions Link
CVE-2024-29171, CVE-2024-29172 Dell BSAFE SSL-J Versions prior to 6.6 Version 6.6 How To Request a Dell BSAFE product download
CVE-2024-29171, CVE-2024-29172 Dell BSAFE SSL-J Versions 7.0 through 7.2 Version 7.2.1 How To Request a Dell BSAFE product download


 

These issues may be mitigated by a workaround, if the customer’s implementations are deemed vulnerable. Customers with an active maintenance contract can contact BSAFE Support for details about the workarounds.

Revisionsverlauf

RevisionDateDescription
1.02024-07-02Initial Release
2.02024-07-31Formatting changes only.  No changes to content.
3.02025-02-11Public disclosure of CVE details.
4.02025-02-12Added version numbers to CVE descriptions and updated the versions in the affected product list.   

Zugehörige Informationen

Betroffene Produkte

BSAFE SSL-J
Artikeleigenschaften
Artikelnummer: 000226620
Artikeltyp: Dell Security Advisory
Zuletzt geändert: 12 Feb. 2025
Antworten auf Ihre Fragen erhalten Sie von anderen Dell NutzerInnen
Support Services
Prüfen Sie, ob Ihr Gerät durch Support Services abgedeckt ist.