DSA-2025-100: Dell BSAFE™ Crypto-J Security Update

Podsumowanie: Dell BSAFE Crypto-J remediation is available to address a vulnerability that could be exploited by malicious users to compromise the affected system.

Ten artykuł dotyczy Ten artykuł nie dotyczy Ten artykuł nie jest powiązany z żadnym konkretnym produktem. Nie wszystkie wersje produktu zostały zidentyfikowane w tym artykule.

Skutki

Medium

Szczegóły

 

 

Proprietary Code CVE Description CVSS Base Score CVSS Vector String
CVE-2025-26333

Dell BSAFE Crypto-J generates an error message that includes sensitive information about its environment and associated data. A remote attacker could potentially exploit this vulnerability, leading to information exposure. 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N 
Proprietary Code CVE Description CVSS Base Score CVSS Vector String
CVE-2025-26333

Dell BSAFE Crypto-J generates an error message that includes sensitive information about its environment and associated data. A remote attacker could potentially exploit this vulnerability, leading to information exposure. 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N 
Firma Dell Technologies zaleca wszystkim klientom uwzględnienie zarówno wyniku podstawowego CVSS, jak i wszelkich istotnych wyników czasowych i środowiskowych, które mogą mieć wpływ na potencjalną dotkliwość związaną z konkretną luką w zabezpieczeniach.

Produkty, których dotyczy problem, i środki zaradcze

Product

Affected versions

Remediated versions

Link

Dell BSAFE Crypto-J

Versions 6.0 through 6.3.0.1

Version 6.3.1

Dell BSAFE™ Crypto-J 6.3.1 Release Advisory

Dell BSAFE Crypto-J

Version 7.0

Version 7.0.1

Dell BSAFE™ Crypto-J 7.0.1 Release Advisory

 

Product

Affected versions

Remediated versions

Link

Dell BSAFE Crypto-J

Versions 6.0 through 6.3.0.1

Version 6.3.1

Dell BSAFE™ Crypto-J 6.3.1 Release Advisory

Dell BSAFE Crypto-J

Version 7.0

Version 7.0.1

Dell BSAFE™ Crypto-J 7.0.1 Release Advisory

 

Obejścia problemu i środki zaradcze

These issues may be mitigated by a workaround, if the customer’s implementations are deemed vulnerable. Customers with an active maintenance contract can contact BSAFE Support for details about the workarounds.

Historia zmian

RevisionDateDescription
1.0 2025-03-17Initial release
2.02025-05-15Updated the links in the Affected Products and Remediation table
3.02025-09-25CVE ID, CVSS score, CVSS vector string, and vulnerability details publicly disclosed.
4.02025-10-10Updated for enhanced presentation with no changes to content

Powiązane informacje

Produkty, których dotyczy problem

BSAFE Crypto-J
Właściwości artykułu
Numer artykułu: 000296144
Typ artykułu: Dell Security Advisory
Ostatnia modyfikacja: 10 paź 2025
Znajdź odpowiedzi na swoje pytania u innych użytkowników produktów Dell
Usługi pomocy technicznej
Sprawdź, czy Twoje urządzenie jest objęte usługą pomocy technicznej.