5 results (0.005 seconds)

CVSS: 10.0EPSS: 2%CPEs: 2EXPL: 0

27 Nov 2017 — EMC RSA Authentication Agent API 8.5 for C and RSA Authentication Agent SDK 8.6 for C allow attackers to bypass authentication, aka an "Error Handling Vulnerability." RSA Authentication Agent API 8.5 para C y RSA Authentication Agent SDK 8.6 para C de EMC permiten que atacantes omitan la autenticación. Esto se conoce como "Error Handling Vulnerability." A security vulnerability in RSA Authentication Agent API/SDK for C versions 8.5 and 8.6 could potentially lead to authentication bypass in certain limited i... • http://seclists.org/fulldisclosure/2017/Nov/48 •

CVSS: 7.5EPSS: 0%CPEs: 2EXPL: 0

24 Oct 2013 — EMC RSA Authentication Agent 7.1.x before 7.1.2 for Web for Internet Information Services has a fail-open design, which allows remote attackers to bypass intended access restrictions via vectors that trigger an agent crash. EMC RSA Authentication Agent 7.1.x anteriores a 7.1.2 para Web para Internet Information Services tienes un diseño abierto a fallos, lo que permite a atacantes remotos sortear las restricciones de acceso a traves de vectores que producen un crash del agente. In certain circumstances, RSA... • http://archives.neohapsis.com/archives/bugtraq/2013-10/0115.html • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 9.8EPSS: 0%CPEs: 3EXPL: 0

20 Aug 2013 — EMC RSA Authentication Agent for PAM 7.0 before 7.0.2.1 enforces the maximum number of login attempts within the PAM-enabled application codebase, instead of within the Agent codebase, which makes it easier for remote attackers to discover correct login credentials via a brute-force attack. EMC RSA Authentication Agent para PAM v7.0 anterior a v7.0.2.1 hace cumplir el número máximo de intentos de conexión del código base cuando PAM está habilitado, en lugar de en el código base del Agente, lo que hace que s... • http://archives.neohapsis.com/archives/bugtraq/2013-08/0123.html • CWE-255: Credentials Management Errors •

CVSS: 6.1EPSS: 0%CPEs: 4EXPL: 0

22 May 2013 — Cross-site scripting (XSS) vulnerability in EMC RSA Authentication Agent 7.1 before 7.1.1 for Web for Internet Information Services, and 7.1 before 7.1.1 for Web for Apache, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad XSS en EMC RSA Authentication Agent 7.1 anterior a 7.1.1 en IIS, y 7.1 anterior a 7.1.1 para Apache, permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de vectores no especificados. • http://archives.neohapsis.com/archives/bugtraq/2013-05/0043.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 8.5EPSS: 0%CPEs: 4EXPL: 0

25 Sep 2012 — The authentication functionality in EMC RSA Authentication Agent 7.1 and RSA Authentication Client 3.5 on Windows XP and Windows Server 2003, when an unspecified configuration exists, allows remote authenticated users to bypass an intended token-authentication step, and establish a login session to a remote host, by leveraging Windows credentials for that host. La funcionalidad de autenticación en EMC RSA Authentication Client v7.1 y RSA Authentication v3.5 en Windows XP y Windows Server 2003, con una confi... • http://archives.neohapsis.com/archives/bugtraq/2012-09/0102.html • CWE-287: Improper Authentication •