CVE-2020-29508
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Improper Input Validation Vulnerability.
Affected (11)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.1.5 | |
| Before 4.6 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 12.1.0.2 | |
| Version 12.2.1.3.0 | |
| Version 12.2.1.3.0 | |
| Version 12.2.1.3.0 |
Related CWEs
CWE-20
Improper Input Validation
The product receives input or data, but it does
not validate or incorrectly validates that the input has the
properties that are required to process the data safely and
correctly.
CWE-331
Insufficient Entropy
The product uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.
References (4)
Source: security_alert@emc.com
Vendor Advisory
Source: security_alert@emc.com
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Timeline
No history available yet.