LOW · 2.1

CVE-2013-0941

EMC RSA Authentication API before 8.1 SP1, RSA Web Agent before 5.3.5 for Apache Web Server, RSA Web Agent before 5.3.5 for IIS, RSA PAM Agent before 7.0, and RSA Agent before 6.1.4 for Microsoft Wind...

Vulnerability Description

EMC RSA Authentication API before 8.1 SP1, RSA Web Agent before 5.3.5 for Apache Web Server, RSA Web Agent before 5.3.5 for IIS, RSA PAM Agent before 7.0, and RSA Agent before 6.1.4 for Microsoft Windows use an improper encryption algorithm and a weak key for maintaining the stored data of the node secret for the SecurID Authentication API, which allows local users to obtain sensitive information via cryptographic attacks on this data.

CVSS Score

2.1

LOW

AV:L/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
RsaAuthentication Api<= 8.1
RsaSecurid Web Agent<= 5.3.4
ApacheHttp ServerAll versions
MicrosoftInternet Information ServerAll versions
RsaPluggable Authentication Module Agent<= 6.0
RsaAuthentication Agent<= 6.1.3
MicrosoftWindowsAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2013-0941?

CVE-2013-0941 is a vulnerability with a CVSS score of 2.1 (LOW). EMC RSA Authentication API before 8.1 SP1, RSA Web Agent before 5.3.5 for Apache Web Server, RSA Web Agent before 5.3.5 for IIS, RSA PAM Agent before 7.0, and RSA Agent before 6.1.4 for Microsoft Wind...

How severe is CVE-2013-0941?

CVE-2013-0941 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2013-0941?

Check the references section above for vendor advisories and patch information. Affected products include: Rsa Authentication Api, Rsa Securid Web Agent, Apache Http Server, Microsoft Internet Information Server, Rsa Pluggable Authentication Module Agent.