Описание
EMC RSA Authentication Agent 7.1.x before 7.1.2 on Windows does not enforce the Quick PIN Unlock timeout feature, which allows physically proximate attackers to bypass the passcode requirement for a screensaved session by entering a PIN after timeout expiration.
Комментарий
Per http://archives.neohapsis.com/archives/bugtraq/2013-03/att-0001/ESA-2013-012.txt "Affected Products:
Product: RSA Authentication Agent for Microsoft Windows version 7.1 and 7.1.1
Platforms: Windows XP and Windows 2003"
Уязвимые конфигурации
Одновременно
Одно из
Одно из
EPSS
5.4 Medium
CVSS2
Дефекты
Связанные уязвимости
EMC RSA Authentication Agent 7.1.x before 7.1.2 on Windows does not enforce the Quick PIN Unlock timeout feature, which allows physically proximate attackers to bypass the passcode requirement for a screensaved session by entering a PIN after timeout expiration.
EPSS
5.4 Medium
CVSS2