Back

CVE-2018-11058

CRITICAL

RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6 (in 4.1.x), and RSA BSAFE Crypto-C Micro Edition, version prior to 4.0.5.3 (in 4.0.x) contain a Buffer Over-Read vulnerability when parsing ASN.1 data. A remote attacker could use maliciously constructed ASN.1 data that would result in such issue.

Published: Sep 14, 2018 Modified: Jun 17, 2026
CWE-125

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (25)

Vendor Product Version
dell bsafe * ≥ 4.0.0 < 4.0.11
dell bsafe * ≥ 4.1.0 < 4.1.6
dell bsafe_crypto-c * ≥ 4.0.0 < 4.0.5.3
oracle application_testing_suite 13.3.0.1
oracle communications_analytics 12.1.1
oracle communications_ip_service_activator 7.3.0
oracle communications_ip_service_activator 7.4.0
oracle core_rdbms 11.2.0.4
oracle core_rdbms 12.1.0.2
oracle core_rdbms 12.2.0.1
oracle core_rdbms 18c
oracle core_rdbms 19c
oracle enterprise_manager_ops_center 12.3.3
oracle enterprise_manager_ops_center 12.4.0
oracle goldengate_application_adapters 12.3.2.1.0
oracle jd_edwards_enterpriseone_tools 9.2
oracle real_user_experience_insight 13.1.2.1
oracle real_user_experience_insight 13.2.3.1
oracle real_user_experience_insight 13.3.1.0
oracle retail_predictive_application_server 15.0.3

…and 5 more

GitHub Security Advisory GHSA-6pm8-q9vc-vxxj

RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6 (in 4.1.x),...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 4.01%

Top 10% most likely to be exploited

Threat Score 40.4 / 100

Data Sources

NVD EPSS GitHub