CVE-2012-2287: High severity rsa authentication agent vulnerability
The authentication functionality in EMC RSA Authentication Agent 7.1 and RSA Authentication Client 3.5 on Windows XP and Windows Server 2003, when an unspecified configuration exists, allows remote authenticated users to bypass an intended token-authentication step, and establish a login session to a remote host, by leveraging Windows credentials for that host.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2287?
CVE-2012-2287 is classified as a medium severity vulnerability.
How do I fix CVE-2012-2287?
To fix CVE-2012-2287, update the EMC RSA Authentication Agent to version 7.1 or the RSA Authentication Client to version 3.5 if applicable.
Who is affected by CVE-2012-2287?
CVE-2012-2287 affects users of EMC RSA Authentication Agent 7.1 and RSA Authentication Client 3.5 running on Windows XP and Windows Server 2003.
What can attackers do with CVE-2012-2287?
Attackers can bypass the intended token-authentication step, allowing unauthorized login sessions.
Is CVE-2012-2287 exploitable remotely?
Yes, CVE-2012-2287 can be exploited by remote authenticated users.