← back
CVE-2023-28077mediumCWE-1295

CVE-2023-28077

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 4.4epss 0.2%
exploitation probability
0.2%top 93% of all CVEs
observed exploitation
nono source reports it
In short

Dell BSAFE SSL-J versions before 6.5, and versions 7.0-7.1, leak sensitive information through debug messages that can be read by users with local system access. This could expose details meant to be hidden.

Technical detail

A debug message information disclosure vulnerability in Dell BSAFE SSL-J (versions <6.5, 7.0, 7.1) allows local privileged users to access sensitive data not intended for disclosure. The vulnerability requires local access to the affected system; impact is limited to information exposure rather than system compromise.

Summary generated and translated by AI from the official description.
Dell BSAFE SSL-J, versions prior to 6.5, and versions 7.0 and 7.1 contain a debug message revealing unnecessary information vulnerability. This may lead to disclosing sensitive information to a locally privileged user.
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Affected products
Dell · Dell BSAFE SSL-J