Lucene search

K
nvd[email protected]NVD:CVE-2013-0941
HistoryMay 22, 2013 - 1:29 p.m.

CVE-2013-0941

2013-05-2213:29:45
CWE-310
web.nvd.nist.gov
8

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

AI Score

5.6

Confidence

Low

EPSS

0

Percentile

5.1%

EMC RSA Authentication API before 8.1 SP1, RSA Web Agent before 5.3.5 for Apache Web Server, RSA Web Agent before 5.3.5 for IIS, RSA PAM Agent before 7.0, and RSA Agent before 6.1.4 for Microsoft Windows use an improper encryption algorithm and a weak key for maintaining the stored data of the node secret for the SecurID Authentication API, which allows local users to obtain sensitive information via cryptographic attacks on this data.

Affected configurations

Nvd
Node
rsaauthentication_apiRange8.1
Node
rsasecurid_web_agentRange5.3.4
AND
apachehttp_server
Node
rsasecurid_web_agentRange5.3.4
AND
microsoftinternet_information_server
Node
rsapluggable_authentication_module_agentRange6.0
Node
rsaauthentication_agentRange6.1.3
AND
microsoftwindows
VendorProductVersionCPE
rsaauthentication_api*cpe:2.3:a:rsa:authentication_api:*:*:*:*:*:*:*:*
rsasecurid_web_agent*cpe:2.3:a:rsa:securid_web_agent:*:*:*:*:*:*:*:*
apachehttp_server*cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*
microsoftinternet_information_server*cpe:2.3:a:microsoft:internet_information_server:*:*:*:*:*:*:*:*
rsapluggable_authentication_module_agent*cpe:2.3:a:rsa:pluggable_authentication_module_agent:*:*:*:*:*:*:*:*
rsaauthentication_agent*cpe:2.3:a:rsa:authentication_agent:*:*:*:*:*:*:*:*
microsoftwindows*cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

AI Score

5.6

Confidence

Low

EPSS

0

Percentile

5.1%

Related for NVD:CVE-2013-0941