CVE-2023-28077: Infoleak
Published Feb 10, 2024
·Updated
Dell BSAFE SSL-J, versions prior to 6.5, and versions 7.0 and 7.1 contain a debug message revealing unnecessary information vulnerability. This may lead to disclosing sensitive information to a locally privileged user.
Affected Software
2 affected components
Dell BSAFE SSL-J>=6.0<6.5.1
Dell BSAFE SSL-J>=7.0<7.1.1
Event History
Feb 10, 2024
CVE Published
via MITRE·03:11 AM
Data Sourced
via MITRE·03:11 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-28077?
CVE-2023-28077 has a moderate severity rating due to the potential for sensitive information disclosure.
2
How do I fix CVE-2023-28077?
To fix CVE-2023-28077, upgrade to Dell BSAFE SSL-J version 6.5.1 or later, or 7.1.1 or later.
3
Who is affected by CVE-2023-28077?
CVE-2023-28077 affects users of Dell BSAFE SSL-J versions prior to 6.5 and 7.0 through 7.1.
4
What kind of information is disclosed in CVE-2023-28077?
CVE-2023-28077 may disclose unnecessary debug messages that could include sensitive information.
5
Is CVE-2023-28077 a local or remote vulnerability?
CVE-2023-28077 is a local vulnerability that could be exploited by a locally privileged user.