CVE-2017-8006: Medium severity rsa authentication manager vulnerability
In EMC RSA Authentication Manager 8.2 SP1 Patch 1 and earlier, a malicious user logged into the Self-Service Console of RSA Authentication Manager as a target user can use a brute force attack to attempt to identify that user's PIN. The malicious user could potentially reset the compromised PIN to affect victim's ability to obtain access to protected resources.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-8006?
CVE-2017-8006 is classified as a high severity vulnerability due to the potential for a brute force attack on user PINs.
How do I fix CVE-2017-8006?
To fix CVE-2017-8006, upgrade to EMC RSA Authentication Manager 8.2 SP1 Patch 2 or later.
What systems are affected by CVE-2017-8006?
CVE-2017-8006 affects EMC RSA Authentication Manager versions 8.2 SP1 and earlier.
What type of attack does CVE-2017-8006 enable?
CVE-2017-8006 enables a brute force attack on user PINs via the Self-Service Console.
Who can exploit CVE-2017-8006?
A malicious user with access to the Self-Service Console can exploit CVE-2017-8006 to compromise user PINs.