← Vulnerability feed

Vulnerability record · CVE-2019-3738 · published 18 September 2019

CVE-2019-3738: Dell bsafe cert-j improper verification of cryptographic signature vulnerability

Dell · Bsafe Cert J

RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to a Missing Required Cryptographic Step vulnerability. A malicious remote attacker could potentially exploit this vulnerability to coerce two parties into computing the same predictable shared key.

6.5 CVSS 3.1 Medium EPSS 1.7% · top 24.0% CWE-325 · CWE-325CWE-347 · Improper verification of cryptographic signature
6.5CVSS 3.1 base score, v2 4.3
1.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
16Affected product versions listed by NVD
16References
17 Jun 2026Last modified by NVD

Description

RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to a Missing Required Cryptographic Step vulnerability. A malicious remote attacker could potentially exploit this vulnerability to coerce two parties into computing the same predictable shared key.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Affected products

16 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-3738 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-34381Dell bsafe ssl-j vulnerabilityDell BSAFE SSL-J version 7.0 and all versions prior to 6.5, and Dell BSAFE Crypto-J versions prior to 6.2.6.1 contain an unmaintained third-party com…EPSS 0.98%9.1CVE-2026-46858Oracle application performance management improper access control vulnerabilityVulnerability in the APM - Application Performance Management product of Oracle Enterprise Manager (component: JADM, JVM Diagnostics). Supported vers…EPSS 0.45%8.3CVE-2021-2351Oracle advanced networking option broken cryptographic algorithm vulnerabilityVulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and …EPSS 2.4%7.5CVE-2025-26333Dell bsafe crypto-j error message information leak vulnerabilityDell BSAFE Crypto-J generates an error message that includes sensitive information about its environment and associated data. A remote attacker could…EPSS 0.33%7.5CVE-2024-29171Dell bsafe ssl-j improper certificate validation vulnerabilityDell BSAFE SSL-J, versions prior to 6.6 and versions 7.0 through 7.2, contains an Improper certificate verification vulnerability. A remote attacker …EPSS 0.33%7.5CVE-2024-29172Dell bsafe ssl-j vulnerabilityDell BSAFE SSL-J, versions prior to 6.6 and versions 7.0 through 7.2, contains a deadlock vulnerability. A remote attacker could potentially exploit …EPSS 0.45%7.5CVE-2022-24409Dell bsafe ssl-j vulnerabilityDell BSAFE SSL-J contains remediation for a covert timing channel vulnerability that may be exploited by malicious users to compromise the affected s…EPSS 0.96%7.5CVE-2016-8212Dell bsafe crypto-j improper resource shutdown vulnerabilityAn issue was discovered in EMC RSA BSAFE Crypto-J versions prior to 6.2.2. There is an Improper OCSP Validation Vulnerability. OCSP responses have tw…EPSS 1.9%

Source: NIST National Vulnerability Database (record CVE-2019-3738), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.