9.8

CVE-2020-29508

Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Improper Input Validation Vulnerability.

Data is provided by the National Vulnerability Database (NVD)
DellBsafe Crypto-c-micro-edition Version < 4.1.5
DellBsafe Micro-edition-suite Version < 4.6
OracleDatabase Version12.1.0.2 SwEditionenterprise
OracleDatabase Version19c SwEditionenterprise
OracleDatabase Version21c SwEditionenterprise
OracleHTTP Server Version12.2.1.3.0
OracleHTTP Server Version12.2.1.4.0
OracleSecurity Service Version12.2.1.3.0
OracleSecurity Service Version12.2.1.4.0
OracleWeblogic Server Proxy Plug-in Version12.2.1.3.0
OracleWeblogic Server Proxy Plug-in Version12.2.1.4.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.24% 0.462
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
security_alert@emc.com 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

CWE-331 Insufficient Entropy

The product uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.