Stack-based buffer overflow in IISWebAgentIF.dll in RSA Authentication Agent for Web (aka SecurID Web Agent) 5.2 and 5.3 for IIS allows remote attackers to execute arbitrary code via a long url parameter in the Redirect method.
CVSS Vector
AV:N/AC:L/Au:N/C:N/I:P/A:PRsa Authentication Agent For Web
APPRsa5.25.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEMemory
References
Related vulnerabilities
CVE-2017-14377CRITICAL9.8PL ✓same product
Authentication bypass w RSA Authentication Agent for Web (Apache)
CVE-2018-1232HIGH7.5same product
RSA Authentication Agent version 8.0.1 and earlier for Web for both IIS and Apache Web Server are impacted by ...
CVE-2018-1233MEDIUM6.1same product
RSA Authentication Agent version 8.0.1 and earlier for Web for both IIS and Apache Web Server are affected by ...
CVE-2018-1234MEDIUM5.5same product
RSA Authentication Agent version 8.0.1 and earlier for Web for IIS is affected by a problem where access contr...
CVE-2010-3261MEDIUM5.0same product
Directory traversal vulnerability in RSA Authentication Agent 7.0 before P2 for Web allows remote attackers to...