Vulnerability Details CVE-2015-0534
EMC RSA BSAFE Micro Edition Suite (MES) 4.0.x before 4.0.8 and 4.1.x before 4.1.3, RSA BSAFE Crypto-J before 6.2, RSA BSAFE SSL-J before 6.2, and RSA BSAFE SSL-C 2.8.9 and earlier do not enforce certain constraints on certificate data, which allows remote attackers to defeat a fingerprint-based certificate-blacklist protection mechanism by including crafted data within a certificate's unsigned portion, a similar issue to CVE-2014-8275.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 57.7%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2015-0534
-
cpe:2.3:a:dell:bsafe:4.0.0
-
cpe:2.3:a:dell:bsafe:4.0.1
-
cpe:2.3:a:dell:bsafe:4.0.2
-
cpe:2.3:a:dell:bsafe:4.0.3
-
cpe:2.3:a:dell:bsafe:4.0.4
-
cpe:2.3:a:dell:bsafe:4.0.5
-
cpe:2.3:a:dell:bsafe:4.0.5.3
-
cpe:2.3:a:dell:bsafe:4.0.7
-
cpe:2.3:a:dell:bsafe:4.1.0
-
cpe:2.3:a:dell:bsafe:4.1.0.1
-
cpe:2.3:a:dell:bsafe:4.1.1
-
cpe:2.3:a:dell:bsafe:4.1.2
-
cpe:2.3:a:dell:bsafe_ssl-c:2.8
-
cpe:2.3:a:dell:bsafe_ssl-c:2.8.7
-
cpe:2.3:a:dell:bsafe_ssl-c:2.8.9
-
cpe:2.3:a:dell:bsafe_ssl-j:-
-
cpe:2.3:a:dell:bsafe_ssl-j:3.0
-
cpe:2.3:a:dell:bsafe_ssl-j:3.0.1
-
cpe:2.3:a:dell:bsafe_ssl-j:3.1
-
cpe:2.3:a:dell:bsafe_ssl-j:5.0
-
cpe:2.3:a:dell:bsafe_ssl-j:5.1
-
cpe:2.3:a:dell:bsafe_ssl-j:5.1.1
-
cpe:2.3:a:dell:bsafe_ssl-j:5.1.2
-
cpe:2.3:a:dell:bsafe_ssl-j:5.1.3
-
cpe:2.3:a:dell:bsafe_ssl-j:5.1.4
-
cpe:2.3:a:dell:bsafe_ssl-j:5.2
-
cpe:2.3:a:dell:bsafe_ssl-j:6.0
-
cpe:2.3:a:dell:bsafe_ssl-j:6.0.1
-
cpe:2.3:a:dell:bsafe_ssl-j:6.0.2
-
cpe:2.3:a:dell:bsafe_ssl-j:6.1
-
cpe:2.3:a:dell:bsafe_ssl-j:6.1.1
-
cpe:2.3:a:dell:bsafe_ssl-j:6.1.2
-
cpe:2.3:a:dell:bsafe_ssl-j:6.1.3
-
cpe:2.3:a:dell:bsafe_ssl-j:6.1.4