First published: Wed May 22 2013(Updated: )
EMC RSA Authentication API before 8.1 SP1, RSA Web Agent before 5.3.5 for Apache Web Server, RSA Web Agent before 5.3.5 for IIS, RSA PAM Agent before 7.0, and RSA Agent before 6.1.4 for Microsoft Windows use an improper encryption algorithm and a weak key for maintaining the stored data of the node secret for the SecurID Authentication API, which allows local users to obtain sensitive information via cryptographic attacks on this data.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
RSA Authentication API | <=8.1 | |
RSA SecurID Web Agent | <=5.3.4 | |
Apache HTTP Server | ||
Microsoft Internet Information Server | ||
Rsa Pluggable Authentication Module Agent | <=6.0 | |
RSA Authentication Agent | <=6.1.3 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-0941 is categorized as a high severity vulnerability due to improper encryption and weak key management.
To fix CVE-2013-0941, upgrade the affected RSA products to their respective patched versions as specified by the vendor.
CVE-2013-0941 affects several RSA products including Authentication API prior to 8.1 SP1 and various versions of RSA Web Agent.
CVE-2013-0941 can be exploited by attackers to gain unauthorized access to sensitive stored data due to weak encryption.
If you are using RSA Authentication API versions earlier than 8.1 SP1, it is vulnerable to CVE-2013-0941.