CVE-2015-0534
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
EMC RSA BSAFE Micro Edition Suite (MES) 4.0.x before 4.0.8 and 4.1.x before 4.1.3, RSA BSAFE Crypto-J before 6.2, RSA BSAFE SSL-J before 6.2, and RSA BSAFE SSL-C 2.8.9 and earlier do not enforce certain constraints on certificate data, which allows remote attackers to defeat a fingerprint-based certificate-blacklist protection mechanism by including crafted data within a certificate's unsigned portion, a similar issue to CVE-2014-8275.
Vulnerabilidad en EMC RSA BSAFE Micro Edition Suite (MES) 4.0.x en versiones anteriores a 4.0.8 y 4.1.x en versiones anteriores a 4.1.3, RSA BSAFE Crypto-J en versiones anteriores a 6.2, RSA BSAFE SSL-J en versiones anteriores a 6.2 y RSA BSAFE SSL-C 2.8.9 y versiones anteriores, no fuerza ciertas restricciones en datos de certificado, lo que permite a atacantes remotos anular el mecanismo de protección de lista negra de certificados basado en fingerprint mediante la inclusión de datos manipulados en una porción sin firmar de un certificado, un problema similar a CVE-2014-8275.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-12-17 CVE Reserved
- 2015-08-17 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-295: Improper Certificate Validation
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://seclists.org/bugtraq/2015/Aug/84 | Mailing List | |
http://www.securityfocus.com/bid/76377 | Third Party Advisory | |
http://www.securitytracker.com/id/1033297 | Third Party Advisory | |
http://www.securitytracker.com/id/1033298 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Dell Search vendor "Dell" | Bsafe Search vendor "Dell" for product "Bsafe" | >= 4.0.0 < 4.0.8 Search vendor "Dell" for product "Bsafe" and version " >= 4.0.0 < 4.0.8" | micro_edition_suite |
Affected
| ||||||
Dell Search vendor "Dell" | Bsafe Search vendor "Dell" for product "Bsafe" | >= 4.1.0 < 4.1.3 Search vendor "Dell" for product "Bsafe" and version " >= 4.1.0 < 4.1.3" | micro_edition_suite |
Affected
| ||||||
Dell Search vendor "Dell" | Bsafe Ssl-c Search vendor "Dell" for product "Bsafe Ssl-c" | <= 2.8.9 Search vendor "Dell" for product "Bsafe Ssl-c" and version " <= 2.8.9" | - |
Affected
| ||||||
Dell Search vendor "Dell" | Bsafe Ssl-j Search vendor "Dell" for product "Bsafe Ssl-j" | < 6.2 Search vendor "Dell" for product "Bsafe Ssl-j" and version " < 6.2" | - |
Affected
|