CVE-2014-0636
RSA BSAFE Micro Edition Suite Certificate Chain Processing
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
EMC RSA BSAFE Micro Edition Suite (MES) 3.2.x before 3.2.6 and 4.0.x before 4.0.5 does not properly validate X.509 certificate chains, which allows man-in-the-middle attackers to spoof SSL servers via a crafted certificate chain.
EMC RSA BSAFE Micro Edition Suite (MES) 3.2.x anterior a 3.2.6 y 4.0.x anterior a 4.0.5 no valida debidamente cadenas de certificados X.509, lo que permite a atacantes man-in-the-middle falsificar servidores SSL a través de una cadena de certificados manipulada.
RSA BSAFE MES 3.2.6, 4.0.5 and higher contains a fix for a security vulnerability that could potentially be exploited by malicious users to create improperly authenticated SSL connections. This vulnerability may cause creation of improperly authenticated SSL connections between the client and the server due to incorrect certificate chain processing logic. MES 4.0.5 and 3.2.6 are designed to address this issue by performing proper certificate validation.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-01-02 CVE Reserved
- 2014-04-11 CVE Published
- 2024-08-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-310: Cryptographic Issues
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://archives.neohapsis.com/archives/bugtraq/2014-04/0069.html | Broken Link | |
http://www.securityfocus.com/bid/66791 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Dell Search vendor "Dell" | Bsafe Micro-edition-suite Search vendor "Dell" for product "Bsafe Micro-edition-suite" | 3.2.0 Search vendor "Dell" for product "Bsafe Micro-edition-suite" and version "3.2.0" | - |
Affected
| ||||||
Dell Search vendor "Dell" | Bsafe Micro-edition-suite Search vendor "Dell" for product "Bsafe Micro-edition-suite" | 3.2.1 Search vendor "Dell" for product "Bsafe Micro-edition-suite" and version "3.2.1" | - |
Affected
| ||||||
Dell Search vendor "Dell" | Bsafe Micro-edition-suite Search vendor "Dell" for product "Bsafe Micro-edition-suite" | 3.2.2 Search vendor "Dell" for product "Bsafe Micro-edition-suite" and version "3.2.2" | - |
Affected
| ||||||
Dell Search vendor "Dell" | Bsafe Micro-edition-suite Search vendor "Dell" for product "Bsafe Micro-edition-suite" | 3.2.3 Search vendor "Dell" for product "Bsafe Micro-edition-suite" and version "3.2.3" | - |
Affected
| ||||||
Dell Search vendor "Dell" | Bsafe Micro-edition-suite Search vendor "Dell" for product "Bsafe Micro-edition-suite" | 3.2.4 Search vendor "Dell" for product "Bsafe Micro-edition-suite" and version "3.2.4" | - |
Affected
| ||||||
Dell Search vendor "Dell" | Bsafe Micro-edition-suite Search vendor "Dell" for product "Bsafe Micro-edition-suite" | 3.2.5 Search vendor "Dell" for product "Bsafe Micro-edition-suite" and version "3.2.5" | - |
Affected
| ||||||
Dell Search vendor "Dell" | Bsafe Micro-edition-suite Search vendor "Dell" for product "Bsafe Micro-edition-suite" | 4.0.0 Search vendor "Dell" for product "Bsafe Micro-edition-suite" and version "4.0.0" | - |
Affected
| ||||||
Dell Search vendor "Dell" | Bsafe Micro-edition-suite Search vendor "Dell" for product "Bsafe Micro-edition-suite" | 4.0.1 Search vendor "Dell" for product "Bsafe Micro-edition-suite" and version "4.0.1" | - |
Affected
| ||||||
Dell Search vendor "Dell" | Bsafe Micro-edition-suite Search vendor "Dell" for product "Bsafe Micro-edition-suite" | 4.0.2 Search vendor "Dell" for product "Bsafe Micro-edition-suite" and version "4.0.2" | - |
Affected
| ||||||
Dell Search vendor "Dell" | Bsafe Micro-edition-suite Search vendor "Dell" for product "Bsafe Micro-edition-suite" | 4.0.3 Search vendor "Dell" for product "Bsafe Micro-edition-suite" and version "4.0.3" | - |
Affected
| ||||||
Dell Search vendor "Dell" | Bsafe Micro-edition-suite Search vendor "Dell" for product "Bsafe Micro-edition-suite" | 4.0.4 Search vendor "Dell" for product "Bsafe Micro-edition-suite" and version "4.0.4" | - |
Affected
|