Wasn't DualEC the default algorithm used by a bunch of RSA products that were incorporated elsewhere?
Later
There was also a period during which the Red Hat Secure Server that shipped with Red Hat Professional linked against BSAFE. Its release timing doesn't square with Dual_EC though.