← Vulnerability feed

Vulnerability record · CVE-2007-6755 · published 11 October 2013

CVE-2007-6755: Dell bsafe crypto-c-micro-edition broken cryptographic algorithm vulnerability

Dell · Bsafe Crypto C Micro Edition

The NIST SP 800-90A default statement of the Dual Elliptic Curve Deterministic Random Bit Generation (Dual_EC_DRBG) algorithm contains point Q constants with a possible relationship to certain "skeleton key" values, which might allow context-dependent attackers to defeat cryptographic protection mechanisms by leveraging knowledge of those values. NOTE: this is a preliminary CVE for Dual_EC_DRBG; future research may provide additional details about point Q and associated attacks, and could potentially lead to a RECAST or REJECT of this CVE.

5.8 CVSS 2.0 Medium EPSS 1.6% · top 24.7% CWE-327 · Broken cryptographic algorithm
5.8CVSS 2.0 base score
1.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
16References
16 Jun 2026Last modified by NVD

Description

The NIST SP 800-90A default statement of the Dual Elliptic Curve Deterministic Random Bit Generation (Dual_EC_DRBG) algorithm contains point Q constants with a possible relationship to certain "skeleton key" values, which might allow context-dependent attackers to defeat cryptographic protection mechanisms by leveraging knowledge of those values. NOTE: this is a preliminary CVE for Dual_EC_DRBG; future research may provide additional details about point Q and associated attacks, and could potentially lead to a RECAST or REJECT of this CVE.

AV:N/AC:M/Au:N/C:P/I:P/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-6755 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-34381Dell bsafe ssl-j vulnerabilityDell BSAFE SSL-J version 7.0 and all versions prior to 6.5, and Dell BSAFE Crypto-J versions prior to 6.2.6.1 contain an unmaintained third-party com…EPSS 0.98%9.8CVE-2020-29504Dell bsafe crypto-c-micro-edition improper certificate validation vulnerabilityDell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain a Missing Required Crypt…EPSS 0.49%9.8CVE-2020-29506Dell bsafe crypto-c-micro-edition vulnerabilityDell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain an Observable Timing Dis…EPSS 1.2%9.8CVE-2020-29507Dell bsafe crypto-c-micro-edition improper input validation vulnerabilityDell BSAFE Crypto-C Micro Edition, versions before 4.1.4, and Dell BSAFE Micro Edition Suite, versions before 4.4, contain an Improper Input Validati…EPSS 1.1%9.8CVE-2020-29508Dell bsafe crypto-c-micro-edition improper input validation vulnerabilityDell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Improper Input Validati…EPSS 1.2%9.8CVE-2020-35163Dell bsafe crypto-c-micro-edition vulnerabilityDell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain a Use of Insufficiently Ra…EPSS 1.1%9.8CVE-2020-35166Dell bsafe crypto-c-micro-edition vulnerabilityDell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timing Discr…EPSS 0.72%9.8CVE-2020-35167Dell bsafe crypto-c-micro-edition information exposure vulnerabilityDell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timing Discr…EPSS 1.0%

Source: NIST National Vulnerability Database (record CVE-2007-6755), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.