← Vulnerability feed

Vulnerability record · CVE-2019-3740 · published 18 September 2019

CVE-2019-3740: Dell bsafe cert-j observable discrepancy vulnerability

Dell · Bsafe Cert J

RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to an Information Exposure Through Timing Discrepancy vulnerabilities during DSA key generation. A malicious remote attacker could potentially exploit those vulnerabilities to recover DSA keys.

6.5 CVSS 3.1 Medium EPSS 3.8% · top 10.5% CWE-310 · CWE-310CWE-203 · Observable discrepancy
6.5CVSS 3.1 base score, v2 4.3
3.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
18Affected product versions listed by NVD
14References
17 Jun 2026Last modified by NVD

Description

RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to an Information Exposure Through Timing Discrepancy vulnerabilities during DSA key generation. A malicious remote attacker could potentially exploit those vulnerabilities to recover DSA keys.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Affected products

18 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-3740 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-34381Dell bsafe ssl-j vulnerabilityDell BSAFE SSL-J version 7.0 and all versions prior to 6.5, and Dell BSAFE Crypto-J versions prior to 6.2.6.1 contain an unmaintained third-party com…EPSS 0.98%9.8CVE-2022-23305Log4j 1.x JDBCAppender SQL injection via logged inputThe JDBCAppender in Log4j 1.2.x builds SQL statements from configuration parameters and PatternLayout converters, so logged values such as the %m mes…EPSS 67%analysed9.8CVE-2019-17571Apache Log4j 1.2 SocketServer Deserialization RCELog4j 1.2 includes a SocketServer class that deserializes untrusted data received over the network. When a deserialization gadget is present on the c…EPSS 69%analysed9.8CVE-2019-2904Oracle application testing suite vulnerabilityVulnerability in the Oracle JDeveloper and ADF product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 1…EPSS 14%9.8CVE-2019-2729Oracle WebLogic Server Web Services improper access control RCECVE-2019-2729 is an improper access control flaw (CWE-284) in the Web Services subcomponent of Oracle WebLogic Server, affecting versions 10.3.6.0.0,…EPSS 89%analysed9.8CVE-2017-5645Apache Log4j 2 socket server deserialization allows remote code executionApache Log4j 2.x before 2.8.2 deserializes binary log events received over its TCP or UDP socket server without validating the payload. A crafted ser…EPSS 90%analysed9.1CVE-2026-46858Oracle application performance management improper access control vulnerabilityVulnerability in the APM - Application Performance Management product of Oracle Enterprise Manager (component: JADM, JVM Diagnostics). Supported vers…EPSS 0.45%8.8CVE-2022-23302Apache Log4j 1.x JMSSink JNDI deserialization remote code executionJMSSink in all versions of Log4j 1.x deserializes untrusted data when an attacker can write to the Log4j configuration or when the configuration refe…EPSS 64%analysed

Source: NIST National Vulnerability Database (record CVE-2019-3740), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.