CVE-2014-0640 describes an access restriction bypass vulnerability in EMC RSA Archer GRC Platform 5.x prior to version 5.5 SP1, allowing remote authenticated users to access unauthorized resources. With a CVSS score of 4.0, this vulnerability is of medium severity, requiring authentication (Au:S) and low attack complexity (AC:L) to achieve partial confidentiality impact (C:P). There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or KEV listing. Despite a single media article mentioning it in the context of Iranian hackers, this CVE has minimal community discussion and a very low EPSS score, indicating a low likelihood of future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.3CPE matchmatch criteria | cpe:2.3:a:emc:rsa_archer_egrc:5.3:*:*:*:*:*:*:* | ||
5.4CPE matchmatch criteria | cpe:2.3:a:emc:rsa_archer_egrc:5.4:*:*:*:*:*:*:* | ||
5.4CPE matchmatch criteria | cpe:2.3:a:emc:rsa_archer_egrc:5.4:sp1:*:*:*:*:*:* | ||
5.5CPE matchmatch criteria | cpe:2.3:a:emc:rsa_archer_egrc:5.5:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:S/C:P/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.