CVE-2014-0643: High severity EMC RSA NetWitness vulnerability
EMC RSA NetWitness before 9.8.5.19 and RSA Security Analytics before 10.2.4 and 10.3.x before 10.3.2, when Kerberos PAM is enabled, do not require a password, which allows remote attackers to bypass authentication by leveraging knowledge of a valid account name.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0643?
CVE-2014-0643 is classified as a critical vulnerability due to its ability to allow remote attackers to bypass authentication.
How do I fix CVE-2014-0643?
To fix CVE-2014-0643, upgrade EMC RSA NetWitness to version 9.8.5.19 or later, and RSA Security Analytics to version 10.2.4 or later.
Which systems are affected by CVE-2014-0643?
CVE-2014-0643 affects EMC RSA NetWitness versions prior to 9.8.5.19 and RSA Security Analytics versions before 10.2.4 and 10.3.x versions before 10.3.2.
What types of attacks can exploit CVE-2014-0643?
CVE-2014-0643 can be exploited through authentication bypass attacks that use a valid account name without requiring a password.
Is there a workaround for CVE-2014-0643?
Currently, the best approach for CVE-2014-0643 is to apply the recommended software updates to mitigate the vulnerability.