7.5

CVE-2011-2733

EMC RSA Adaptive Authentication On-Premise (AAOP) 6.0.2.1 SP1 Patch 2, SP1 Patch 3, SP2, SP2 Patch 1, and SP3 does not prevent reuse of authentication information during a session, which allows remote authenticated users to bypass intended access restrictions via vectors related to knowledge of the originally used authentication information and unspecified other session information.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
EmcRsa Adaptive Authentication On-premise Version6.0.2.1 Updatesp1_patch2
EmcRsa Adaptive Authentication On-premise Version6.0.2.1 Updatesp1_patch3
EmcRsa Adaptive Authentication On-premise Version6.0.2.1 Updatesp2
EmcRsa Adaptive Authentication On-premise Version6.0.2.1 Updatesp2_patch1
EmcRsa Adaptive Authentication On-premise Version6.0.2.1 Updatesp3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.358
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 6.8 8.5
AV:N/AC:M/Au:S/C:C/I:P/A:P
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.