Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2013-0941


EMC RSA Authentication API before 8.1 SP1, RSA Web Agent before 5.3.5 for Apache Web Server, RSA Web Agent before 5.3.5 for IIS, RSA PAM Agent before 7.0, and RSA Agent before 6.1.4 for Microsoft Windows use an improper encryption algorithm and a weak key for maintaining the stored data of the node secret for the SecurID Authentication API, which allows local users to obtain sensitive information via cryptographic attacks on this data.


Published

2013-05-22T13:29:45.513

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 2.1 (LOW)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:P/I:N/A:N

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

3.9

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-310

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application rsa authentication_api ≤ 8.1 Yes
Application rsa securid_web_agent ≤ 5.3.4 Yes
Application apache http_server * No
Application rsa securid_web_agent ≤ 5.3.4 Yes
Application microsoft internet_information_server * No
Application rsa pluggable_authentication_module_agent ≤ 6.0 Yes
Application rsa authentication_agent ≤ 6.1.3 Yes
Operating System microsoft windows * No

References