Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-25qv-mpwh-3c2j

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью

Описание

RSA Adaptive Authentication (On-Premise) 6.0.2.1 through 7.1 P3, when using device binding in a Challenge SOAP call or using the RSA Adaptive Authentication Integration Adapters with Out-of-Band Phone (Authentify) functionality, conducts permanent device binding even when authentication fails, which allows remote attackers to bypass authentication.

RSA Adaptive Authentication (On-Premise) 6.0.2.1 through 7.1 P3, when using device binding in a Challenge SOAP call or using the RSA Adaptive Authentication Integration Adapters with Out-of-Band Phone (Authentify) functionality, conducts permanent device binding even when authentication fails, which allows remote attackers to bypass authentication.

EPSS

Процентиль: 76%
0.00999
Низкий

Дефекты

CWE-287

Связанные уязвимости

nvd
почти 11 лет назад

RSA Adaptive Authentication (On-Premise) 6.0.2.1 through 7.1 P3, when using device binding in a Challenge SOAP call or using the RSA Adaptive Authentication Integration Adapters with Out-of-Band Phone (Authentify) functionality, conducts permanent device binding even when authentication fails, which allows remote attackers to bypass authentication.

EPSS

Процентиль: 76%
0.00999
Низкий

Дефекты

CWE-287