Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.
Some article numbers may have changed. If this isn't what you're looking for, try searching all articles. Search articles

Article Number: 000203278


DSA-2022-208: Dell BSAFE SSL-J 6.5 and 7.1 and Dell BSAFE Crypto-J 6.2.6.1 and 7.0 Security Vulnerability

Summary: Dell BSAFE SSL-J and Dell BSAFE Crypto-J contain remediation for a vulnerability that may be exploited by malicious users to compromise the affected system.

Article Content


Impact

Critical

Details

Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2022-34381 Dell BSAFE SSL-J version 7.0 and all versions prior to 6.5, and Dell BSAFE Crypto-J versions prior to 6.2.6.1 contain an unmaintained third-party component vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to the compromise of the impacted system. This is a Critical vulnerability and Dell recommends customers to upgrade at the earliest opportunity. 9.1 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2022-34381 Dell BSAFE SSL-J version 7.0 and all versions prior to 6.5, and Dell BSAFE Crypto-J versions prior to 6.2.6.1 contain an unmaintained third-party component vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to the compromise of the impacted system. This is a Critical vulnerability and Dell recommends customers to upgrade at the earliest opportunity. 9.1 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products and Remediation

 
CVE(s) addressed Product Affected Versions Remediated Versions Link
CVE-2022-34381 Dell BSAFE SSL-J Versions prior to 6.5, and version 7.0 Version 6.5 and 7.1 How To Request a Dell BSAFE product download
CVE-2022-34381 Dell BSAFE Crypto-J
 
Versions prior to 6.2.6.1
 
Version 6.2.6.1 and 7.0
 
How To Request a Dell BSAFE product download
 
CVE(s) addressed Product Affected Versions Remediated Versions Link
CVE-2022-34381 Dell BSAFE SSL-J Versions prior to 6.5, and version 7.0 Version 6.5 and 7.1 How To Request a Dell BSAFE product download
CVE-2022-34381 Dell BSAFE Crypto-J
 
Versions prior to 6.2.6.1
 
Version 6.2.6.1 and 7.0
 
How To Request a Dell BSAFE product download

Workarounds and Mitigations

Workarounds or mitigation may exist based on individual use case and usage of the product. Only customers with active BSAFE maintenance contracts can receive details about the vulnerabilities, including possible workaround or mitigations.

Revision History

Revision DateDescription
1.02022-09-12Initial Release.
2.02023-08-08Major Revision: disclosing CVE iD, CVSS score, details.
3.0 2023-08-08Minor formatting changes without content change.

Related Information


Article Properties


Affected Product

BSAFE Crypto-J, BSAFE SSL-J

Last Published Date

08 Aug 2023

Article Type

Dell Security Advisory