PT-2017-18064 · Emc · Emc Rsa Authentication Manager

Publicado

2017-07-17

·

Atualizado

2017-08-10

·

CVE-2017-8006

CVSS v3.1

5.9

Média

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions EMC RSA Authentication Manager versions 8.2 SP1 Patch 1 and earlier
Description A malicious user logged into the Self-Service Console of RSA Authentication Manager can use a brute force attack to attempt to identify a target user's PIN. This could potentially allow the malicious user to reset the compromised PIN, affecting the victim's ability to obtain access to protected resources.
Recommendations For EMC RSA Authentication Manager versions 8.2 SP1 Patch 1 and earlier, consider implementing additional security measures to prevent brute force attacks, such as rate limiting or IP blocking, until a patch is available. As a temporary workaround, restrict access to the Self-Service Console to minimize the risk of exploitation.

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-8006

Produtos afetados

Emc Rsa Authentication Manager