CVE-2018-1232
RSA Authentication Agent for Web XSS / Buffer Overflow
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
RSA Authentication Agent version 8.0.1 and earlier for Web for both IIS and Apache Web Server are impacted by a stack-based buffer overflow which may occur when handling certain malicious web cookies that have invalid formats. The attacker could exploit this vulnerability to crash the authentication agent and cause a denial-of-service situation.
RSA Authentication Agent en versiones 8.0.1 y anteriores para Web para IIS y Apache Web Server se ve afectado por un desbordamiento de búfer basado en pila que puede ocurrir cuando se manipulan determinadas cookies web maliciosas que tienen formatos no válidos. El atacante podría explotar esta vulnerabilidad para cerrar de manera inesperada el agente de autenticación y provocar una situación de denegación de servicio (DoS).
RSA Authentication Agent for Web for both IIS and Apache Web Server version 8.0. 1 and earlier contain multiple vulnerabilities that could potentially be exploit ed by malicious users to compromise affected systems. These issues include cross site scripting, buffer overflow, and information disclosure.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-12-06 CVE Reserved
- 2018-03-28 CVE Published
- 2024-09-17 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-787: Out-of-bounds Write
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://seclists.org/fulldisclosure/2018/Mar/60 | Mailing List |
|
http://www.securitytracker.com/id/1040577 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Rsa Search vendor "Rsa" | Authentication Agent For Web Search vendor "Rsa" for product "Authentication Agent For Web" | <= 8.0.1 Search vendor "Rsa" for product "Authentication Agent For Web" and version " <= 8.0.1" | apache_web_server |
Affected
| ||||||
Rsa Search vendor "Rsa" | Authentication Agent For Web Search vendor "Rsa" for product "Authentication Agent For Web" | <= 8.0.1 Search vendor "Rsa" for product "Authentication Agent For Web" and version " <= 8.0.1" | iis |
Affected
|