EMC RSA Authentication Agent 7.1.x before 7.1.2 on Windows does not enforce the Quick PIN Unlock timeout feature, which allows physically proximate attackers to bypass the passcode requirement for a screensaved session by entering a PIN after timeout expiration.
oryginał ENCVSS Vector
AV:A/AC:M/Au:N/C:P/I:P/A:PMicrosoft Windows 2003 Server
OSMicrosoftwszystkie wersjeMicrosoft Windows Xp
OSMicrosoftwszystkie wersjeRsa Authentication Agent For Windows
APPRsa7.17.1.1
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Powiązane podatności
CVE-2014-1776CRITICAL9.8⚠ KEVPL ✓ten sam produkt
Use-after-free w Microsoft Internet Explorer 6–11 umożliwia RCE
CVE-2008-4250CRITICAL9.8⚠ KEVPL ✓ten sam produkt
RCE w usłudze Server systemu Windows przez przepełnienie bufora w RPC
CVE-2024-47856CRITICAL9.8PL ✓ten sam produkt
RSA Authentication Agent – podatność path interception (unquoted service path)
CVE-2019-5620CRITICAL9.8PL ✓ten sam produkt
Brak uwierzytelnienia dla krytycznej funkcji w ABB MicroSCADA Pro SYS600
CVE-2020-7485CRITICAL9.8PL ✓ten sam produkt
Ukryte konto serwisowe w Schneider Electric TriStation umożliwia nieautoryzowany dostęp