Vulnerability Description
RSA Netwitness Platform versions prior to 11.2.1.1 and RSA Security Analytics versions prior to 10.6.6.1 are vulnerable to a Command Injection vulnerability due to missing input validation in the product. A remote unauthenticated malicious user could exploit this vulnerability to execute arbitrary commands on the server.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rsa | Netwitness | < 11.2.1.1 |
| Rsa | Security Analytics | < 10.6.6.1 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/108355
- https://community.rsa.com/docs/DOC-104202Vendor Advisory
- http://www.securityfocus.com/bid/108355
- https://community.rsa.com/docs/DOC-104202Vendor Advisory
FAQ
What is CVE-2019-3725?
CVE-2019-3725 is a vulnerability with a CVSS score of 9.8 (CRITICAL). RSA Netwitness Platform versions prior to 11.2.1.1 and RSA Security Analytics versions prior to 10.6.6.1 are vulnerable to a Command Injection vulnerability due to missing input validation in the prod...
How severe is CVE-2019-3725?
CVE-2019-3725 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-3725?
Check the references section above for vendor advisories and patch information. Affected products include: Rsa Netwitness, Rsa Security Analytics.