CVE-2015-0537 is an integer underflow vulnerability in the base64-decoding implementation of EMC RSA BSAFE Micro Edition Suite, Crypto-C Micro Edition, and SSL-C. This critical vulnerability (CVSS 9.8) allows remote attackers to cause a denial of service through memory corruption or segmentation faults, or potentially achieve other unspecified impacts, by providing crafted base64 data. The attack requires no user interaction and has low attack complexity, posing a significant risk to confidentiality, integrity, and availability. Despite its high severity, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.0.0, < 4.0.8CPE matchmatch criteria | cpe:2.3:a:dell:bsafe:*:*:*:*:micro_edition_suite:*:*:* | ||
>= 4.1.0, < 4.1.3CPE matchmatch criteria | cpe:2.3:a:dell:bsafe:*:*:*:*:micro_edition_suite:*:*:* | ||
< 4.0.4CPE matchmatch criteria | cpe:2.3:a:dell:bsafe_crypto-c:*:*:*:*:micro_edition:*:*:* | ||
<= 2.8.9CPE matchmatch criteria | cpe:2.3:a:dell:bsafe_ssl-c:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.