PT-2014-3336 · Vasco · Vasco Identikey Authentication Server

Luke Sullivan

+1

·

Publicado

2014-01-13

·

Atualizado

2014-01-14

·

CVE-2013-7292

CVSS v2.0

3.5

Baixa

VetorAV:N/AC:M/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions VASCO IDENTIKEY Authentication Server (IAS) version 3.4.x
Description The issue allows remote authenticated users to bypass Active Directory authentication. This is done by entering only a DIGIPASS one-time password, instead of the required combination of this one-time password and a multiple-time AD password.
Recommendations For version 3.4.x, consider restricting access to the DIGIPASS one-time password feature until a fix is available, to minimize the risk of Active Directory authentication bypass.

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-7292

Produtos afetados

Vasco Identikey Authentication Server