9.8

CVE-2020-29506

Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain an Observable Timing Discrepancy Vulnerability.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DellBsafe Crypto-c-micro-edition Version < 4.1.5
DellBsafe Micro-edition-suite Version < 4.5.2
OracleDatabase Version12.1.0.2 SwEditionenterprise
OracleDatabase Version19c SwEditionenterprise
OracleDatabase Version21c SwEditionenterprise
OracleHTTP Server Version12.2.1.3.0
OracleHTTP Server Version12.2.1.4.0
OracleSecurity Service Version12.2.1.3.0
OracleSecurity Service Version12.2.1.4.0
OracleWeblogic Server Proxy Plug-in Version12.2.1.3.0
OracleWeblogic Server Proxy Plug-in Version12.2.1.4.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.33% 0.791
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
security_alert@emc.com 6.8 2.2 4
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
CWE-385 Covert Timing Channel

Covert timing channels convey information by modulating some aspect of system behavior over time, so that the program receiving the information can observe system behavior and infer protected information.