← Vulnerability feed

Vulnerability record · CVE-2022-24409 · published 23 February 2022

CVE-2022-24409: Dell bsafe ssl-j vulnerability

Dell · Bsafe Ssl J

Dell BSAFE SSL-J contains remediation for a covert timing channel vulnerability that may be exploited by malicious users to compromise the affected system. Only customers with active BSAFE maintenance contracts can receive details about this vulnerability. Public disclosure of the vulnerability details will be shared at a later date.

7.5 CVSS 3.1 High EPSS 0.96% · top 39.9% CWE-385 · CWE-385
7.5CVSS 3.1 base score, v2 7.5
0.96%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Dell BSAFE SSL-J contains remediation for a covert timing channel vulnerability that may be exploited by malicious users to compromise the affected system. Only customers with active BSAFE maintenance contracts can receive details about this vulnerability. Public disclosure of the vulnerability details will be shared at a later date.

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-24409 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-34381Dell bsafe ssl-j vulnerabilityDell BSAFE SSL-J version 7.0 and all versions prior to 6.5, and Dell BSAFE Crypto-J versions prior to 6.2.6.1 contain an unmaintained third-party com…EPSS 0.98%7.5CVE-2024-29171Dell bsafe ssl-j improper certificate validation vulnerabilityDell BSAFE SSL-J, versions prior to 6.6 and versions 7.0 through 7.2, contains an Improper certificate verification vulnerability. A remote attacker …EPSS 0.33%7.5CVE-2024-29172Dell bsafe ssl-j vulnerabilityDell BSAFE SSL-J, versions prior to 6.6 and versions 7.0 through 7.2, contains a deadlock vulnerability. A remote attacker could potentially exploit …EPSS 0.45%7.5CVE-2015-0534Dell bsafe improper certificate validation vulnerabilityEMC RSA BSAFE Micro Edition Suite (MES) 4.0.x before 4.0.8 and 4.1.x before 4.1.3, RSA BSAFE Crypto-J before 6.2, RSA BSAFE SSL-J before 6.2, and RSA…EPSS 1.4%7.5CVE-2004-0079Cisco firewall services module null pointer dereference vulnerabilityThe do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) vi…EPSS 9.5%7.5CVE-2001-1105Cisco icdn vulnerabilityRSA BSAFE SSL-J 3.0, 3.0.1 and 3.1, as used in Cisco iCND 2.0, caches session IDs from failed login attempts, which could allow remote attackers to b…EPSS 2.7%6.5CVE-2019-3738Dell bsafe cert-j improper verification of cryptographic signature vulnerabilityRSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to a Missing Required Cryptographic Step vulnerability. A malicious remote attacker could p…EPSS 1.7%6.5CVE-2019-3739Dell bsafe cert-j observable discrepancy vulnerabilityRSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to Information Exposure Through Timing Discrepancy vulnerabilities during ECDSA key generat…EPSS 2.5%

Source: NIST National Vulnerability Database (record CVE-2022-24409), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.