CVE-2020-35166

EUVD-2020-22854
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timing Discrepancy Vulnerability.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.1 MEDIUM
LOCAL
HIGH
NONE
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
dellCNA
5.1 MEDIUM
LOCAL
HIGH
NONE
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 64%
Affected Products (NVD)
VendorProductVersion
dellbsafe_crypto-c-micro-edition
𝑥
< 4.1.5
dellbsafe_micro-edition-suite
𝑥
< 4.6
oracledatabase
12.1.0.2
oraclehttp_server
12.2.1.3.0
oraclehttp_server
12.2.1.4.0
oraclesecurity_service
12.2.1.3.0
oraclesecurity_service
12.2.1.4.0
oracleweblogic_server_proxy_plug-in
12.2.1.3.0
oracleweblogic_server_proxy_plug-in
12.2.1.4.0
𝑥
= Vulnerable software versions