EMC RSA Authentication Agent 7.1.x before 7.1.2 on Windows does not enforce the Quick PIN Unlock timeout feature, which allows physically proximate attackers to bypass the passcode requirement for a screensaved session by entering a PIN after timeout expiration.
CVSS Vector
AV:A/AC:M/Au:N/C:P/I:P/A:PMicrosoft Windows 2003 Server
OSMicrosoftall versionsMicrosoft Windows Xp
OSMicrosoftall versionsRsa Authentication Agent For Windows
APPRsa7.17.1.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2014-1776CRITICAL9.8⚠ KEVPL ✓same product
Use-after-free w Microsoft Internet Explorer 6–11 umożliwia RCE
CVE-2008-4250CRITICAL9.8⚠ KEVPL ✓same product
RCE w usłudze Server systemu Windows przez przepełnienie bufora w RPC
CVE-2024-47856CRITICAL9.8PL ✓same product
RSA Authentication Agent – podatność path interception (unquoted service path)
CVE-2019-5620CRITICAL9.8PL ✓same product
Brak uwierzytelnienia dla krytycznej funkcji w ABB MicroSCADA Pro SYS600
CVE-2020-7485CRITICAL9.8PL ✓same product
Ukryte konto serwisowe w Schneider Electric TriStation umożliwia nieautoryzowany dostęp