// For flags

CVE-2014-0636

RSA BSAFE Micro Edition Suite Certificate Chain Processing

Severity Score

5.9
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

EMC RSA BSAFE Micro Edition Suite (MES) 3.2.x before 3.2.6 and 4.0.x before 4.0.5 does not properly validate X.509 certificate chains, which allows man-in-the-middle attackers to spoof SSL servers via a crafted certificate chain.

EMC RSA BSAFE Micro Edition Suite (MES) 3.2.x anterior a 3.2.6 y 4.0.x anterior a 4.0.5 no valida debidamente cadenas de certificados X.509, lo que permite a atacantes man-in-the-middle falsificar servidores SSL a través de una cadena de certificados manipulada.

RSA BSAFE MES 3.2.6, 4.0.5 and higher contains a fix for a security vulnerability that could potentially be exploited by malicious users to create improperly authenticated SSL connections. This vulnerability may cause creation of improperly authenticated SSL connections between the client and the server due to incorrect certificate chain processing logic. MES 4.0.5 and 3.2.6 are designed to address this issue by performing proper certificate validation.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2014-01-02 CVE Reserved
  • 2014-04-11 CVE Published
  • 2024-08-06 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-310: Cryptographic Issues
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Dell
Search vendor "Dell"
Bsafe Micro-edition-suite
Search vendor "Dell" for product "Bsafe Micro-edition-suite"
3.2.0
Search vendor "Dell" for product "Bsafe Micro-edition-suite" and version "3.2.0"
-
Affected
Dell
Search vendor "Dell"
Bsafe Micro-edition-suite
Search vendor "Dell" for product "Bsafe Micro-edition-suite"
3.2.1
Search vendor "Dell" for product "Bsafe Micro-edition-suite" and version "3.2.1"
-
Affected
Dell
Search vendor "Dell"
Bsafe Micro-edition-suite
Search vendor "Dell" for product "Bsafe Micro-edition-suite"
3.2.2
Search vendor "Dell" for product "Bsafe Micro-edition-suite" and version "3.2.2"
-
Affected
Dell
Search vendor "Dell"
Bsafe Micro-edition-suite
Search vendor "Dell" for product "Bsafe Micro-edition-suite"
3.2.3
Search vendor "Dell" for product "Bsafe Micro-edition-suite" and version "3.2.3"
-
Affected
Dell
Search vendor "Dell"
Bsafe Micro-edition-suite
Search vendor "Dell" for product "Bsafe Micro-edition-suite"
3.2.4
Search vendor "Dell" for product "Bsafe Micro-edition-suite" and version "3.2.4"
-
Affected
Dell
Search vendor "Dell"
Bsafe Micro-edition-suite
Search vendor "Dell" for product "Bsafe Micro-edition-suite"
3.2.5
Search vendor "Dell" for product "Bsafe Micro-edition-suite" and version "3.2.5"
-
Affected
Dell
Search vendor "Dell"
Bsafe Micro-edition-suite
Search vendor "Dell" for product "Bsafe Micro-edition-suite"
4.0.0
Search vendor "Dell" for product "Bsafe Micro-edition-suite" and version "4.0.0"
-
Affected
Dell
Search vendor "Dell"
Bsafe Micro-edition-suite
Search vendor "Dell" for product "Bsafe Micro-edition-suite"
4.0.1
Search vendor "Dell" for product "Bsafe Micro-edition-suite" and version "4.0.1"
-
Affected
Dell
Search vendor "Dell"
Bsafe Micro-edition-suite
Search vendor "Dell" for product "Bsafe Micro-edition-suite"
4.0.2
Search vendor "Dell" for product "Bsafe Micro-edition-suite" and version "4.0.2"
-
Affected
Dell
Search vendor "Dell"
Bsafe Micro-edition-suite
Search vendor "Dell" for product "Bsafe Micro-edition-suite"
4.0.3
Search vendor "Dell" for product "Bsafe Micro-edition-suite" and version "4.0.3"
-
Affected
Dell
Search vendor "Dell"
Bsafe Micro-edition-suite
Search vendor "Dell" for product "Bsafe Micro-edition-suite"
4.0.4
Search vendor "Dell" for product "Bsafe Micro-edition-suite" and version "4.0.4"
-
Affected