CVE-2006-7201: Critical severity emc rsa security sitekey vulnerability
Published Apr 30, 2007
·Updated
EMC RSA Security SiteKey does not set the secure qualifier on the SiteKey Flash token (aka the PassMark Flash shared object), which might allow remote attackers to obtain the token via HTTP.
Affected Software
1 affected component
EMC RSA Security SiteKey
Event History
Apr 30, 2007
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-7201?
CVE-2006-7201 is considered to be of medium severity due to the potential for unauthorized access to Session tokens.
2
How do I fix CVE-2006-7201?
To mitigate CVE-2006-7201, ensure that the SiteKey Flash token is configured to use the secure flag to prevent transmission over HTTP.
3
What software is affected by CVE-2006-7201?
CVE-2006-7201 affects EMC RSA Security SiteKey.
4
Can CVE-2006-7201 be exploited remotely?
Yes, CVE-2006-7201 can potentially be exploited remotely by attackers to capture the SiteKey Flash token.
5
Is CVE-2006-7201 still a risk today?
Depending on the version of EMC RSA Security SiteKey in use, CVE-2006-7201 may still present a risk if not addressed.