In EMC RSA Authentication Manager 8.2 SP1 Patch 1 and earlier, a malicious user logged into the Self-Service Console of RSA Authentication Manager as a target user can use a brute force attack to attempt to identify that user's PIN. The malicious user could potentially reset the compromised PIN to affect victim's ability to obtain access to protected resources.
References
| Link | Resource |
|---|---|
| http://seclists.org/fulldisclosure/2017/Jul/23 | Mailing List Third Party Advisory |
| http://www.securitytracker.com/id/1038879 | Third Party Advisory VDB Entry |
| http://www.securityfocus.com/bid/99554 | Third Party Advisory VDB Entry |
Configurations
Information
Published : 2017-07-17 07:29
Updated : 2017-08-10 08:01
NVD link : CVE-2017-8006
Mitre link : CVE-2017-8006
JSON object : View
CWE
CWE-287
Improper Authentication
Products Affected
emc
- rsa_authentication_manager


