CVE-2015-6851: High severity rsa securid web agent vulnerability
Published Dec 23, 2015
·Updated
EMC RSA SecurID Web Agent before 8.0 allows physically proximate attackers to bypass the privacy-screen protection mechanism by leveraging an unattended workstation and running DOM Inspector.
Affected Software
1 affected component
RSA SecurID Web Agent<=7.2.1
Event History
Dec 23, 2015
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-6851?
CVE-2015-6851 is classified as a medium severity vulnerability.
2
How do I fix CVE-2015-6851?
To fix CVE-2015-6851, upgrade to RSA SecurID Web Agent version 8.0 or later.
3
What type of attack does CVE-2015-6851 facilitate?
CVE-2015-6851 allows local attackers to bypass privacy-screen protections on unattended workstations.
4
Which versions of RSA SecurID Web Agent are affected by CVE-2015-6851?
CVE-2015-6851 affects RSA SecurID Web Agent versions prior to 8.0, up to and including 7.2.1.
5
What is the impact of exploiting CVE-2015-6851?
Exploiting CVE-2015-6851 can lead to unauthorized access to sensitive information by bypassing authentication mechanisms.