DSA-2024-221: Security Update for Dell BSAFE™ SSL-J Multiple Vulnerabilities

概要: Dell BSAFE SSL-J remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.

この記事は次に適用されます: この記事は次には適用されません: この記事は、特定の製品に関連付けられていません。 すべての製品パージョンがこの記事に記載されているわけではありません。

影響

Medium

詳細

Proprietary Code CVEs

Description

CVSS Base Score

CVSS Vector String

CVE-2024-29171

Dell BSAFE SSL-J, versions prior to 6.6 and versions 7.0 through 7.2, contains an Improper certificate verification vulnerability. A remote attacker could potentially exploit this vulnerability, leading to information disclosure.

5.9

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NThis hyperlink is taking you to a website outside of Dell Technologies.

CVE-2024-29172

Dell BSAFE SSL-J, versions prior to 6.6 and versions 7.0 through 7.2, contains a deadlock vulnerability. A remote attacker could potentially exploit this vulnerability, leading to a Denial of Service.

5.9

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HThis hyperlink is taking you to a website outside of Dell Technologies.

Proprietary Code CVEs

Description

CVSS Base Score

CVSS Vector String

CVE-2024-29171

Dell BSAFE SSL-J, versions prior to 6.6 and versions 7.0 through 7.2, contains an Improper certificate verification vulnerability. A remote attacker could potentially exploit this vulnerability, leading to information disclosure.

5.9

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NThis hyperlink is taking you to a website outside of Dell Technologies.

CVE-2024-29172

Dell BSAFE SSL-J, versions prior to 6.6 and versions 7.0 through 7.2, contains a deadlock vulnerability. A remote attacker could potentially exploit this vulnerability, leading to a Denial of Service.

5.9

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HThis hyperlink is taking you to a website outside of Dell Technologies.

デル・テクノロジーズでは、すべてのお客様に対して、CVSSベース スコアに加えて、特定のセキュリティの脆弱性に付随する潜在的な重要度に影響する可能性のある現状スコアや環境スコアも考慮することをお勧めしています。

影響を受ける製品と修復

CVEs Addressed Product Affected Versions Remediated Versions Link
CVE-2024-29171, CVE-2024-29172 Dell BSAFE SSL-J Versions prior to 6.6 Version 6.6 How To Request a Dell BSAFE product download
CVE-2024-29171, CVE-2024-29172 Dell BSAFE SSL-J Versions 7.0 through 7.2 Version 7.2.1 How To Request a Dell BSAFE product download


 

CVEs Addressed Product Affected Versions Remediated Versions Link
CVE-2024-29171, CVE-2024-29172 Dell BSAFE SSL-J Versions prior to 6.6 Version 6.6 How To Request a Dell BSAFE product download
CVE-2024-29171, CVE-2024-29172 Dell BSAFE SSL-J Versions 7.0 through 7.2 Version 7.2.1 How To Request a Dell BSAFE product download


 

These issues may be mitigated by a workaround, if the customer’s implementations are deemed vulnerable. Customers with an active maintenance contract can contact BSAFE Support for details about the workarounds.

変更履歴

RevisionDateDescription
1.02024-07-02Initial Release
2.02024-07-31Formatting changes only.  No changes to content.
3.02025-02-11Public disclosure of CVE details.
4.02025-02-12Added version numbers to CVE descriptions and updated the versions in the affected product list.   

関連情報

対象製品

BSAFE SSL-J
文書のプロパティ
文書番号: 000226620
文書の種類: Dell Security Advisory
最終更新: 12 2月 2025
質問に対する他のDellユーザーからの回答を見つける
サポート サービス
お使いのデバイスがサポート サービスの対象かどうかを確認してください。