← Vulnerability feed

Vulnerability record · CVE-2019-3728 · published 30 September 2019

CVE-2019-3728: Dell bsafe crypto-c out-of-bounds read vulnerability

Dell · Bsafe Crypto C

RSA BSAFE Crypto-C Micro Edition versions from 4.0.0.0 before 4.0.5.4 and from 4.1.0 before 4.1.4, RSA BSAFE Micro Edition Suite versions from 4.0.0 before 4.0.13 and from 4.1.0 before 4.4 and RSA Crypto-C versions from 6.0.0 through 6.4.* are vulnerable to an out-of-bounds read vulnerability when processing DSA signature. A malicious remote user could potentially exploit this vulnerability to cause a crash in the library of the affected system.

7.5 CVSS 3.1 High EPSS 2.4% · top 16.6% CWE-125 · Out-of-bounds read
7.5CVSS 3.1 base score, v2 5.0
2.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

RSA BSAFE Crypto-C Micro Edition versions from 4.0.0.0 before 4.0.5.4 and from 4.1.0 before 4.1.4, RSA BSAFE Micro Edition Suite versions from 4.0.0 before 4.0.13 and from 4.1.0 before 4.4 and RSA Crypto-C versions from 6.0.0 through 6.4.* are vulnerable to an out-of-bounds read vulnerability when processing DSA signature. A malicious remote user could potentially exploit this vulnerability to cause a crash in the library of the affected system.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-3728 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-21575Dell bsafe micro-edition-suite observable discrepancy vulnerabilityDell BSAFE Micro Edition Suite, versions before 4.5.2, contain an Observable Timing Discrepancy Vulnerability.EPSS 0.53%9.8CVE-2020-29504Dell bsafe crypto-c-micro-edition improper certificate validation vulnerabilityDell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain a Missing Required Crypt…EPSS 0.49%9.8CVE-2020-29506Dell bsafe crypto-c-micro-edition vulnerabilityDell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain an Observable Timing Dis…EPSS 1.2%9.8CVE-2020-29507Dell bsafe crypto-c-micro-edition improper input validation vulnerabilityDell BSAFE Crypto-C Micro Edition, versions before 4.1.4, and Dell BSAFE Micro Edition Suite, versions before 4.4, contain an Improper Input Validati…EPSS 1.1%9.8CVE-2020-29508Dell bsafe crypto-c-micro-edition improper input validation vulnerabilityDell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Improper Input Validati…EPSS 1.2%9.8CVE-2020-35163Dell bsafe crypto-c-micro-edition vulnerabilityDell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain a Use of Insufficiently Ra…EPSS 1.1%9.8CVE-2020-35166Dell bsafe crypto-c-micro-edition vulnerabilityDell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timing Discr…EPSS 0.72%9.8CVE-2020-35167Dell bsafe crypto-c-micro-edition information exposure vulnerabilityDell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timing Discr…EPSS 1.0%

Source: NIST National Vulnerability Database (record CVE-2019-3728), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.