CVE-2018-1253 describes a stored cross-site scripting (XSS) vulnerability in RSA Authentication Manager Operation Console versions 8.3 P1 and earlier. A malicious Operations Console administrator could inject arbitrary HTML or JavaScript code into the web interface. This injected code would then execute in the browsers of other administrators viewing the compromised page, potentially leading to information disclosure or unauthorized actions. The vulnerability has a CVSS v3.1 score of 6.1 (Medium), indicating a network-based attack with low complexity, requiring user interaction, and resulting in low impact to confidentiality and integrity. Despite being a medium severity issue, it has a very low EPSS score, suggesting a low probability of exploitation in the wild. Currently, there is no known active exploitation, publicly available exploit code (e.g., Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE. It is not listed in CISA's Known Exploited Vulnerabilities Catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 7.0CPE matchmatch criteria | cpe:2.3:a:emc:rsa_authentication_manager:*:*:*:*:*:*:*:* | ||
7.1CPE matchmatch criteria | cpe:2.3:a:emc:rsa_authentication_manager:7.1:-:*:*:*:*:*:* | ||
7.1CPE matchmatch criteria | cpe:2.3:a:emc:rsa_authentication_manager:7.1:sp2:*:*:*:*:*:* | ||
7.1CPE matchmatch criteria | cpe:2.3:a:emc:rsa_authentication_manager:7.1:sp3:*:*:*:*:*:* | ||
7.1CPE matchmatch criteria | cpe:2.3:a:emc:rsa_authentication_manager:7.1:sp4:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.