CVE-2010-3321: Low severity rsa authentication client vulnerability
RSA Authentication Client 2.0.x, 3.0, and 3.5.x before 3.5.3 does not properly handle a SENSITIVE or NON-EXTRACTABLE tag on a secret key object that is stored on a SecurID 800 authenticator, which allows local users to bypass intended access restrictions and read keys via unspecified PKCS#11 API requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3321?
CVE-2010-3321 is classified as a medium-severity vulnerability due to its potential for local user exploitation.
How do I fix CVE-2010-3321?
To fix CVE-2010-3321, upgrade the RSA Authentication Client to version 3.5.3 or later.
What systems are affected by CVE-2010-3321?
CVE-2010-3321 affects RSA Authentication Client versions 2.0, 3.0, and 3.5.x prior to 3.5.3.
What risk does CVE-2010-3321 pose?
CVE-2010-3321 allows local users to bypass access restrictions and potentially read sensitive keys.
Was CVE-2010-3321 publicly disclosed?
Yes, CVE-2010-3321 was publicly disclosed as part of security advisories related to RSA Authentication Client vulnerabilities.