CVE-2013-0941
Published May 22, 2013
Last updated 11 years ago
Overview
- Description
- EMC RSA Authentication API before 8.1 SP1, RSA Web Agent before 5.3.5 for Apache Web Server, RSA Web Agent before 5.3.5 for IIS, RSA PAM Agent before 7.0, and RSA Agent before 6.1.4 for Microsoft Windows use an improper encryption algorithm and a weak key for maintaining the stored data of the node secret for the SecurID Authentication API, which allows local users to obtain sensitive information via cryptographic attacks on this data.
- Source
- security_alert@emc.com
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 2.1
- Impact score
- 2.9
- Exploitability score
- 3.9
- Vector string
- AV:L/AC:L/Au:N/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-310
Evaluator
- Comment
- Per: http://archives.neohapsis.com/archives/bugtraq/2013-05/att-0064/ESA-2013-029.txt "RSA SecurID Sensitive Information Disclosure Vulnerability"
- Impact
- -
- Solution
- -
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:rsa:authentication_api:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "106A85E9-6CC3-4FEF-B4DC-E2324FCA2EC4", "versionEndIncluding": "8.1" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:rsa:securid_web_agent:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "085DCA9D-174A-4B6E-984B-E870E6B466FC", "versionEndIncluding": "5.3.4" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "5A6CD1F4-4C0E-4989-A2B3-DC086E8E80A3" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:rsa:securid_web_agent:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "085DCA9D-174A-4B6E-984B-E870E6B466FC", "versionEndIncluding": "5.3.4" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:microsoft:internet_information_server:*:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "CE9D333C-76E2-4BD9-B98B-5CB96363AB89" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:rsa:pluggable_authentication_module_agent:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "923ED08F-368E-46EC-AAF4-6B1B924B4280", "versionEndIncluding": "6.0" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:rsa:authentication_agent:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "653BDB04-670F-4E57-A3AA-AE56162F28DB", "versionEndIncluding": "6.1.3" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "2CF61F35-5905-4BA9-AD7E-7DB261D2F256" } ], "operator": "OR" } ], "operator": "AND" } ]