First published: Mon Jul 17 2017(Updated: )
In EMC RSA Authentication Manager 8.2 SP1 Patch 1 and earlier, a malicious user logged into the Self-Service Console of RSA Authentication Manager as a target user can use a brute force attack to attempt to identify that user's PIN. The malicious user could potentially reset the compromised PIN to affect victim's ability to obtain access to protected resources.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
EMC RSA Authentication Manager | <=8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-8006 is classified as a high severity vulnerability due to the potential for a brute force attack on user PINs.
To fix CVE-2017-8006, upgrade to EMC RSA Authentication Manager 8.2 SP1 Patch 2 or later.
CVE-2017-8006 affects EMC RSA Authentication Manager versions 8.2 SP1 and earlier.
CVE-2017-8006 enables a brute force attack on user PINs via the Self-Service Console.
A malicious user with access to the Self-Service Console can exploit CVE-2017-8006 to compromise user PINs.