DSA-2024-221: Security Update for Dell BSAFE™ SSL-J Multiple Vulnerabilities

요약: Dell BSAFE SSL-J remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.

이 문서는 다음에 적용됩니다. 이 문서는 다음에 적용되지 않습니다. 이 문서는 특정 제품과 관련이 없습니다. 모든 제품 버전이 이 문서에 나와 있는 것은 아닙니다.

영향

Medium

세부 정보

Proprietary Code CVEs

Description

CVSS Base Score

CVSS Vector String

CVE-2024-29171

Dell BSAFE SSL-J, versions prior to 6.6 and versions 7.0 through 7.2, contains an Improper certificate verification vulnerability. A remote attacker could potentially exploit this vulnerability, leading to information disclosure.

5.9

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NThis hyperlink is taking you to a website outside of Dell Technologies.

CVE-2024-29172

Dell BSAFE SSL-J, versions prior to 6.6 and versions 7.0 through 7.2, contains a deadlock vulnerability. A remote attacker could potentially exploit this vulnerability, leading to a Denial of Service.

5.9

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HThis hyperlink is taking you to a website outside of Dell Technologies.

Proprietary Code CVEs

Description

CVSS Base Score

CVSS Vector String

CVE-2024-29171

Dell BSAFE SSL-J, versions prior to 6.6 and versions 7.0 through 7.2, contains an Improper certificate verification vulnerability. A remote attacker could potentially exploit this vulnerability, leading to information disclosure.

5.9

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NThis hyperlink is taking you to a website outside of Dell Technologies.

CVE-2024-29172

Dell BSAFE SSL-J, versions prior to 6.6 and versions 7.0 through 7.2, contains a deadlock vulnerability. A remote attacker could potentially exploit this vulnerability, leading to a Denial of Service.

5.9

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HThis hyperlink is taking you to a website outside of Dell Technologies.

Dell Technologies는 모든 고객이 CVSS 기본 점수와 관련 임시 및 환경 점수를 모두 고려할 것을 권장합니다. 이 경우 특정 보안 취약성과 관련된 잠재적인 심각도에 영향을 미칠 수 있습니다.

영향을 받는 제품 및 문제 해결

CVEs Addressed Product Affected Versions Remediated Versions Link
CVE-2024-29171, CVE-2024-29172 Dell BSAFE SSL-J Versions prior to 6.6 Version 6.6 How To Request a Dell BSAFE product download
CVE-2024-29171, CVE-2024-29172 Dell BSAFE SSL-J Versions 7.0 through 7.2 Version 7.2.1 How To Request a Dell BSAFE product download


 

CVEs Addressed Product Affected Versions Remediated Versions Link
CVE-2024-29171, CVE-2024-29172 Dell BSAFE SSL-J Versions prior to 6.6 Version 6.6 How To Request a Dell BSAFE product download
CVE-2024-29171, CVE-2024-29172 Dell BSAFE SSL-J Versions 7.0 through 7.2 Version 7.2.1 How To Request a Dell BSAFE product download


 

These issues may be mitigated by a workaround, if the customer’s implementations are deemed vulnerable. Customers with an active maintenance contract can contact BSAFE Support for details about the workarounds.

개정 내역

RevisionDateDescription
1.02024-07-02Initial Release
2.02024-07-31Formatting changes only.  No changes to content.
3.02025-02-11Public disclosure of CVE details.
4.02025-02-12Added version numbers to CVE descriptions and updated the versions in the affected product list.   

관련 정보

해당 제품

BSAFE SSL-J
문서 속성
문서 번호: 000226620
문서 유형: Dell Security Advisory
마지막 수정 시간: 12 2월 2025
다른 Dell 사용자에게 질문에 대한 답변 찾기
지원 서비스
디바이스에 지원 서비스가 적용되는지 확인하십시오.