CVE Vulnerabilities

CVE-2014-0636

Published: Apr 11, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

EMC RSA BSAFE Micro Edition Suite (MES) 3.2.x before 3.2.6 and 4.0.x before 4.0.5 does not properly validate X.509 certificate chains, which allows man-in-the-middle attackers to spoof SSL servers via a crafted certificate chain.

Affected Software

NameVendorStart VersionEnd Version
Bsafe_micro-edition-suiteDell3.2.0 (including)3.2.0 (including)
Bsafe_micro-edition-suiteDell3.2.1 (including)3.2.1 (including)
Bsafe_micro-edition-suiteDell3.2.2 (including)3.2.2 (including)
Bsafe_micro-edition-suiteDell3.2.3 (including)3.2.3 (including)
Bsafe_micro-edition-suiteDell3.2.4 (including)3.2.4 (including)
Bsafe_micro-edition-suiteDell3.2.5 (including)3.2.5 (including)
Bsafe_micro-edition-suiteDell4.0.0 (including)4.0.0 (including)
Bsafe_micro-edition-suiteDell4.0.1 (including)4.0.1 (including)
Bsafe_micro-edition-suiteDell4.0.2 (including)4.0.2 (including)
Bsafe_micro-edition-suiteDell4.0.3 (including)4.0.3 (including)
Bsafe_micro-edition-suiteDell4.0.4 (including)4.0.4 (including)

References