Stack-based buffer overflow in IISWebAgentIF.dll in RSA Authentication Agent for Web (aka SecurID Web Agent) 5.2 and 5.3 for IIS allows remote attackers to execute arbitrary code via a long url parameter in the Redirect method.
oryginał ENCVSS Vector
AV:N/AC:L/Au:N/C:N/I:P/A:PRsa Authentication Agent For Web
APPRsa5.25.3
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
RCEMemory
Referencje
Powiązane podatności
CVE-2017-14377CRITICAL9.8PL ✓ten sam produkt
Authentication bypass w RSA Authentication Agent for Web (Apache)
CVE-2018-1232HIGH7.5ten sam produkt
RSA Authentication Agent version 8.0.1 and earlier for Web for both IIS and Apache Web Server are impacted by ...
CVE-2018-1233MEDIUM6.1ten sam produkt
RSA Authentication Agent version 8.0.1 and earlier for Web for both IIS and Apache Web Server are affected by ...
CVE-2018-1234MEDIUM5.5ten sam produkt
RSA Authentication Agent version 8.0.1 and earlier for Web for IIS is affected by a problem where access contr...
CVE-2010-3261MEDIUM5.0ten sam produkt
Directory traversal vulnerability in RSA Authentication Agent 7.0 before P2 for Web allows remote attackers to...