5

CVE-2014-4631

RSA Adaptive Authentication (On-Premise) 6.0.2.1 through 7.1 P3, when using device binding in a Challenge SOAP call or using the RSA Adaptive Authentication Integration Adapters with Out-of-Band Phone (Authentify) functionality, conducts permanent device binding even when authentication fails, which allows remote attackers to bypass authentication.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
EmcRsa Adaptive Authentication On-premise Version6.0.2.1 Updatesp1_patch2
EmcRsa Adaptive Authentication On-premise Version6.0.2.1 Updatesp1_patch3
EmcRsa Adaptive Authentication On-premise Version6.0.2.1 Updatesp2
EmcRsa Adaptive Authentication On-premise Version6.0.2.1 Updatesp2_patch1
EmcRsa Adaptive Authentication On-premise Version6.0.2.1 Updatesp3
EmcRsa Adaptive Authentication On-premise Version6.0.2.1 Updatesp3_p3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1% 0.749
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.