CVE-2013-6180
 
Severity Score
6.8
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
EMC RSA Security Analytics (SA) 10.x before 10.3, and RSA NetWitness NextGen 9.8, does not ensure that SA Core requests originate from the SA REST UI, which allows remote attackers to bypass intended access restrictions by sending a Core request from a web browser or other unintended user agent.
EMC RSA Security Analytics (SA) 10.x anterior a 10.3, y RSA NetWitness NextGen 9.8, no asegura que las peticiones al SA Core se originen en el SA REST UI, lo que permite a atacantes remotos evitar las restricciones de acceso al enviar una solicitud Core desde una web navegador u otro agente de usuario no deseado.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2013-10-21 CVE Reserved
- 2013-12-09 CVE Published
- 2024-08-06 CVE Updated
- 2024-10-29 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://archives.neohapsis.com/archives/bugtraq/2013-12/0034.html | Mailing List | |
http://www.securitytracker.com/id/1029446 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Emc Search vendor "Emc" | Rsa Netwitness Nextgen Search vendor "Emc" for product "Rsa Netwitness Nextgen" | 9.8 Search vendor "Emc" for product "Rsa Netwitness Nextgen" and version "9.8" | - |
Affected
| ||||||
Emc Search vendor "Emc" | Rsa Security Analytics Search vendor "Emc" for product "Rsa Security Analytics" | 10.0 Search vendor "Emc" for product "Rsa Security Analytics" and version "10.0" | - |
Affected
| ||||||
Emc Search vendor "Emc" | Rsa Security Analytics Search vendor "Emc" for product "Rsa Security Analytics" | 10.1 Search vendor "Emc" for product "Rsa Security Analytics" and version "10.1" | - |
Affected
| ||||||
Emc Search vendor "Emc" | Rsa Security Analytics Search vendor "Emc" for product "Rsa Security Analytics" | 10.2 Search vendor "Emc" for product "Rsa Security Analytics" and version "10.2" | - |
Affected
|