ID

VAR-201809-1191


CVE

CVE-2018-11068


TITLE

RSA BSAFE SSL-J Vulnerabilities related to security functions

Trust: 0.8

sources: JVNDB: JVNDB-2018-013165

DESCRIPTION

RSA BSAFE SSL-J versions prior to 6.2.4 contain a Heap Inspection vulnerability that could allow an attacker with physical access to the system to recover sensitive key material. RSA BSAFE SSL-J Contains vulnerabilities related to security features.Information may be obtained. Dell EMC RSA BSAFE is a security software product of Dell (Dell), which supports encryption algorithms, certificate chain verification, and Transport Layer Security (TLS) cipher suites, etc., to help users achieve various security goals for their applications . RSA BSAFE SSL-J is one of the SSL toolkits. The vulnerability is caused by the program not properly clearing the heap memory before releasing the memory. An attack in close physical proximity could exploit this vulnerability to recover the key. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 DSA-2018-150:RSA BSAFE(r) SSL-J Multiple Vulnerabilities Dell EMC Identifier: DSA-2018-150 CVE Identifier: CVE-2018-11068, CVE-2018-11069, CVE-2018-11070 Severity: Medium Severity Rating: View details below for individual CVSS Score for each CVE Affected Products: RSA BSAFE Crypto-J versions prior to 6.2.4 RSA BSAFE SSL-J versions prior to 6.2.4 Summary: RSA BSAFE Crypto-J and SSL-J contains fixes for multiple security vulnerabilities that could potentially be exploited by malicious users to compromise the affected system. CVSS v3.0 Base Score: 3.9 (AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N) Covert Timing Channel Vulnerability, CVE-2018-11069 RSA BSAFE SSL-J versions prior to 6.2.4 contain a Covert Timing Channel vulnerability during RSA decryption, also known as a Bleichenbacher attack on RSA decryption. A remote attacker may be able to recover a RSA key. A remote attacker may be able to recover a RSA key. CVSS v3.0 Base Score: 5.9 (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N) Recommendation: The following RSA BSAFE Crypto-J and SSL-J releases contain resolutions to these vulnerabilities: RSA BSAFE Crypto-J version 6.2.4 RSA BSAFE SSL-J version 6.2.4 For additional documentation, downloads, and more, visit the RSA BSAFE page at https://community.rsa.com/community/products/bsafe on RSA Link. Severity Rating: For an explanation of Severity Ratings, refer to the Security Advisories Severity Rating knowledge base article at https://community.rsa.com/docs/DOC-47147. RSA recommends all customers take into account both the base score and any relevant temporal and environmental scores which may impact the potential severity associated with particular security vulnerability. EOPS Policy: RSA has a defined End of Primary Support policy associated with all major versions. Please refer to the Product Version Life Cycle at https://community.rsa.com/docs/DOC-40387 for additional details. Legal Information: Read and use the information in this RSA Security Advisory to assist in avoiding any situation that might arise from the problems described herein. If you have any questions regarding this advisory, contact RSA Customer Support at https://community.rsa.com/docs/DOC-1294. RSA Security LLC and its affiliates, including without limitation, its ultimate parent company, Dell Technologies, distribute RSA Security Advisories in order to bring to the attention of users of the affected RSA products, important security information. RSA recommends that all users determine the applicability of this information to their individual situations and take appropriate action. The information set forth herein is provided "as is" without warranty of any kind. RSA disclaims all warranties, either express or implied, including the warranties of merchantability, fitness for a particular purpose, title and non-infringement. In no event shall RSA, its affiliates or its suppliers, be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if RSA, its affiliates or its suppliers have been advised of the possibility of such damages. Some jurisdictions do not allow the exclusion or limitation of liability for consequential or incidental damages, so the foregoing limitation may not apply. Dell Product Security Incident Response Team (PSIRT) secure@dell.com -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEP5nobPoCj3pTvhAZgSlofD2Yi6cFAluQalwACgkQgSlofD2Y i6fYBBAAi/9xinlt+Inx/esVGjrJRgDKhn2bB+4SR5nwPFlYttl6ePxKW1dY3QQO phnd4hHez0UuyPiPNWNLdbByuT1FKPhyG6/6NnbxZZOyCFSLpP602cYiBkDw31pj HKDI4hKzWnaKLY4N6ghUHzX77I2CO8KIcxkN9r86MK+h0ZfOHxjpJLDIZ8uZ/yhy YvJMTtLCUb8j+a4ozL7zXmsUvc1hU84YhKvuNXsTGhTmc+Iy02fVAIigHKMFspgV mHwVueGdmWVR5k05QaF47sSaGXZcqW1lAOvwxr0u300wrxlryJhQHiZ6fZh8B6VT D/6BX8JNUgyN+teu23rGb7KNKCQmE8Yo72bBg+1C+GDip80r1D2+q1mhzV+aPCib PgASSx+mOPER4T8jVKrpj5bjSGrrOx4BXxDHD6UZyg3gkoA6tGny4h+LUeZgnCx4 t6t5pipDsTm4lX9gPngnWMpKFBI4IBVGeQdDW1IXwvaeR3ePeAc2MMHv4MO23T51 p/8X0aIvSfxBtznElwD3QEkt+qfsrqJ+qQ3QCmg18PPB6REFcP8k8cYuHBKuL/JX 9+n0U6EJvtE+TA+Kj/yqLbZbPtOR98aK8PcZ15yLRtSKSo/swe/Ir26r0oTRVG94 FUPkwX11l36jHhpvziMJMRcYi3FxO+dttEQRsw6fg7A4pUjSN1U= =lYoY -----END PGP SIGNATURE-----

Trust: 1.8

sources: NVD: CVE-2018-11068 // JVNDB: JVNDB-2018-013165 // VULHUB: VHN-120890 // PACKETSTORM: 149269

AFFECTED PRODUCTS

vendor:dellmodel:bsafe ssl-jscope:ltversion:6.2.4

Trust: 1.0

vendor:dell emc old emcmodel:rsa bsafe ssl-jscope:ltversion:6.2.4

Trust: 0.8

vendor:emcmodel:rsa bsafe ssl-jscope:eqversion:6.1.2

Trust: 0.6

sources: JVNDB: JVNDB-2018-013165 // CNNVD: CNNVD-201809-434 // NVD: CVE-2018-11068

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-11068
value: MEDIUM

Trust: 1.0

security_alert@emc.com: CVE-2018-11068
value: LOW

Trust: 1.0

NVD: CVE-2018-11068
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201809-434
value: MEDIUM

Trust: 0.6

VULHUB: VHN-120890
value: LOW

Trust: 0.1

nvd@nist.gov: CVE-2018-11068
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:P/I:N/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-120890
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:P/I:N/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-11068
baseSeverity: MEDIUM
baseScore: 4.6
vectorString: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
attackVector: PHYSICAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 0.9
impactScore: 3.6
version: 3.1

Trust: 1.0

security_alert@emc.com: CVE-2018-11068
baseSeverity: LOW
baseScore: 3.9
vectorString: CVSS:3.0/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
attackVector: PHYSICAL
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 0.3
impactScore: 3.6
version: 3.0

Trust: 1.0

NVD: CVE-2018-11068
baseSeverity: MEDIUM
baseScore: 4.6
vectorString: CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
attackVector: PHYSICAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: VULHUB: VHN-120890 // JVNDB: JVNDB-2018-013165 // CNNVD: CNNVD-201809-434 // NVD: CVE-2018-11068 // NVD: CVE-2018-11068

PROBLEMTYPE DATA

problemtype:CWE-459

Trust: 1.1

problemtype:CWE-254

Trust: 0.8

sources: VULHUB: VHN-120890 // JVNDB: JVNDB-2018-013165 // NVD: CVE-2018-11068

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-201809-434

TYPE

lack of information

Trust: 0.6

sources: CNNVD: CNNVD-201809-434

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-013165

EXPLOIT AVAILABILITY

sources: VULHUB: VHN-120890

PATCH

title:RSA BSAFEurl:https://community.rsa.com/community/products/bsafe

Trust: 0.8

title:Dell EMC RSA BSAFE SSL-J Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=84724

Trust: 0.6

sources: JVNDB: JVNDB-2018-013165 // CNNVD: CNNVD-201809-434

EXTERNAL IDS

db:NVDid:CVE-2018-11068

Trust: 2.6

db:SECTRACKid:1041614

Trust: 1.7

db:JVNDBid:JVNDB-2018-013165

Trust: 0.8

db:CNNVDid:CNNVD-201809-434

Trust: 0.7

db:PACKETSTORMid:149269

Trust: 0.2

db:VULHUBid:VHN-120890

Trust: 0.1

sources: VULHUB: VHN-120890 // JVNDB: JVNDB-2018-013165 // PACKETSTORM: 149269 // CNNVD: CNNVD-201809-434 // NVD: CVE-2018-11068

REFERENCES

url:https://seclists.org/fulldisclosure/2018/sep/7

Trust: 2.5

url:http://www.securitytracker.com/id/1041614

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2018-11068

Trust: 0.9

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-11068

Trust: 0.8

url:https://community.rsa.com/docs/doc-47147.

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2018-11070

Trust: 0.1

url:https://community.rsa.com/docs/doc-40387

Trust: 0.1

url:https://community.rsa.com/community/products/bsafe

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2018-11069

Trust: 0.1

url:https://community.rsa.com/docs/doc-1294.

Trust: 0.1

sources: VULHUB: VHN-120890 // JVNDB: JVNDB-2018-013165 // PACKETSTORM: 149269 // CNNVD: CNNVD-201809-434 // NVD: CVE-2018-11068

SOURCES

db:VULHUBid:VHN-120890
db:JVNDBid:JVNDB-2018-013165
db:PACKETSTORMid:149269
db:CNNVDid:CNNVD-201809-434
db:NVDid:CVE-2018-11068

LAST UPDATE DATE

2024-11-23T21:52:48.527000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-120890date:2021-12-09T00:00:00
db:JVNDBid:JVNDB-2018-013165date:2019-02-15T00:00:00
db:CNNVDid:CNNVD-201809-434date:2019-10-17T00:00:00
db:NVDid:CVE-2018-11068date:2024-11-21T03:42:36.897

SOURCES RELEASE DATE

db:VULHUBid:VHN-120890date:2018-09-11T00:00:00
db:JVNDBid:JVNDB-2018-013165date:2019-02-15T00:00:00
db:PACKETSTORMid:149269date:2018-09-07T14:02:22
db:CNNVDid:CNNVD-201809-434date:2018-09-11T00:00:00
db:NVDid:CVE-2018-11068date:2018-09-11T19:29:01.130