7.5

CVE-2011-2733

EMC RSA Adaptive Authentication On-Premise (AAOP) 6.0.2.1 SP1 Patch 2, SP1 Patch 3, SP2, SP2 Patch 1, and SP3 does not prevent reuse of authentication information during a session, which allows remote authenticated users to bypass intended access restrictions via vectors related to knowledge of the originally used authentication information and unspecified other session information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Emc ≫ Rsa Adaptive Authentication On-premise Version 6.0.2.1 Update sp1_patch2
Emc ≫ Rsa Adaptive Authentication On-premise Version 6.0.2.1 Update sp1_patch3
Emc ≫ Rsa Adaptive Authentication On-premise Version 6.0.2.1 Update sp2
Emc ≫ Rsa Adaptive Authentication On-premise Version 6.0.2.1 Update sp2_patch1
Emc ≫ Rsa Adaptive Authentication On-premise Version 6.0.2.1 Update sp3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.29% 0.665
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 6.8 8.5
AV:N/AC:M/Au:S/C:C/I:P/A:P
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

http://securityreason.com/securityalert/8344
http://www.securityfocus.com/archive/1/519346/100/0/threaded
http://www.securityfocus.com/bid/49574