7.6
CVE-2014-0643
- EPSS 1.21%
- Veröffentlicht 16.05.2014 11:11:59
- Zuletzt bearbeitet 12.04.2025 10:46:40
- Quelle security_alert@emc.com
- Teams Watchlist Login
- Unerledigt Login
EMC RSA NetWitness before 9.8.5.19 and RSA Security Analytics before 10.2.4 and 10.3.x before 10.3.2, when Kerberos PAM is enabled, do not require a password, which allows remote attackers to bypass authentication by leveraging knowledge of a valid account name.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Emc ≫ Rsa Netwitness Version < 9.8.5.19
Emc ≫ Rsa Security Analytics Version >= 10.2 < 10.2.4
Emc ≫ Rsa Security Analytics Version >= 10.3 < 10.3.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 1.21% | 0.77 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7.6 | 4.9 | 10 |
AV:N/AC:H/Au:N/C:C/I:C/A:C
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.