dell bsafe-crypto-c-micro-edition CVE-2020-29508 in Dell and Oracle Products
Published on July 11, 2022

product logo product logo product logo
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Improper Input Validation Vulnerability.

NVD

Vulnerability Analysis

CVE-2020-29508 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity, and a small impact on availability.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
NONE
Integrity Impact:
NONE
Availability Impact:
LOW

Weakness Type

Insufficient Entropy

The software uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.


Products Associated with CVE-2020-29508

You can be notified by email with stack.watch whenever vulnerabilities like CVE-2020-29508 are published in these products:

 
 
 
 
 
 

Affected Versions

Dell BSAFE Micro Edition Suite:

Exploit Probability

EPSS
0.73%
Percentile
72.39%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.