PT-2014-3738 · Rsa Security+1 · Rsa Security Analytics+1

Published

2014-05-16

·

Updated

2018-12-12

·

CVE-2014-0643

CVSS v2.0

7.6

High

VectorAV:N/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions EMC RSA NetWitness versions prior to 9.8.5.19 RSA Security Analytics versions prior to 10.2.4 RSA Security Analytics versions 10.3.x prior to 10.3.2
Description The issue allows remote attackers to bypass authentication by leveraging knowledge of a valid account name when Kerberos PAM is enabled, as no password is required.
Recommendations For EMC RSA NetWitness versions prior to 9.8.5.19, update to version 9.8.5.19 or later. For RSA Security Analytics versions prior to 10.2.4, update to version 10.2.4 or later. For RSA Security Analytics versions 10.3.x prior to 10.3.2, update to version 10.3.2 or later.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-0643

Affected Products

Emc Rsa Netwitness
Rsa Security Analytics