First published: Wed Dec 23 2015(Updated: )
EMC RSA SecurID Web Agent before 8.0 allows physically proximate attackers to bypass the privacy-screen protection mechanism by leveraging an unattended workstation and running DOM Inspector.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
RSA SecurID Web Agent | <=7.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-6851 is classified as a medium severity vulnerability.
To fix CVE-2015-6851, upgrade to RSA SecurID Web Agent version 8.0 or later.
CVE-2015-6851 allows local attackers to bypass privacy-screen protections on unattended workstations.
CVE-2015-6851 affects RSA SecurID Web Agent versions prior to 8.0, up to and including 7.2.1.
Exploiting CVE-2015-6851 can lead to unauthorized access to sensitive information by bypassing authentication mechanisms.