← Vulnerability feed

Vulnerability record · CVE-2022-34381 · published 2 February 2024

CVE-2022-34381: Dell bsafe ssl-j vulnerability

Dell · Bsafe Ssl J

Dell BSAFE SSL-J version 7.0 and all versions prior to 6.5, and Dell BSAFE Crypto-J versions prior to 6.2.6.1 contain an unmaintained third-party component vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to the compromise of the impacted system. This is a Critical vulnerability and Dell recommends customers to upgrade at the earliest opportunity.

9.8 CVSS 3.1 Critical EPSS 0.98% · top 39.3% CWE-1329 · CWE-1329
9.8CVSS 3.1 base score
0.98%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Dell BSAFE SSL-J version 7.0 and all versions prior to 6.5, and Dell BSAFE Crypto-J versions prior to 6.2.6.1 contain an unmaintained third-party component vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to the compromise of the impacted system. This is a Critical vulnerability and Dell recommends customers to upgrade at the earliest opportunity.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-34381 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2025-26333Dell bsafe crypto-j error message information leak vulnerabilityDell BSAFE Crypto-J generates an error message that includes sensitive information about its environment and associated data. A remote attacker could…EPSS 0.33%7.5CVE-2024-29171Dell bsafe ssl-j improper certificate validation vulnerabilityDell BSAFE SSL-J, versions prior to 6.6 and versions 7.0 through 7.2, contains an Improper certificate verification vulnerability. A remote attacker …EPSS 0.33%7.5CVE-2024-29172Dell bsafe ssl-j vulnerabilityDell BSAFE SSL-J, versions prior to 6.6 and versions 7.0 through 7.2, contains a deadlock vulnerability. A remote attacker could potentially exploit …EPSS 0.45%7.5CVE-2022-24409Dell bsafe ssl-j vulnerabilityDell BSAFE SSL-J contains remediation for a covert timing channel vulnerability that may be exploited by malicious users to compromise the affected s…EPSS 0.96%7.5CVE-2016-8212Dell bsafe crypto-j improper resource shutdown vulnerabilityAn issue was discovered in EMC RSA BSAFE Crypto-J versions prior to 6.2.2. There is an Improper OCSP Validation Vulnerability. OCSP responses have tw…EPSS 1.9%7.5CVE-2015-0534Dell bsafe improper certificate validation vulnerabilityEMC RSA BSAFE Micro Edition Suite (MES) 4.0.x before 4.0.8 and 4.1.x before 4.1.3, RSA BSAFE Crypto-J before 6.2, RSA BSAFE SSL-J before 6.2, and RSA…EPSS 1.4%7.5CVE-2004-0079Cisco firewall services module null pointer dereference vulnerabilityThe do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) vi…EPSS 9.5%7.5CVE-2001-1105Cisco icdn vulnerabilityRSA BSAFE SSL-J 3.0, 3.0.1 and 3.1, as used in Cisco iCND 2.0, caches session IDs from failed login attempts, which could allow remote attackers to b…EPSS 2.7%

Source: NIST National Vulnerability Database (record CVE-2022-34381), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.