Rsa Authentication Manager

Vendor:

First CVE: Jul 13, 2012 · Active for 14 years

25
Total CVEs
More Total CVEs than 95% of tracked products
3.1
Avg CVEs / Year
Higher CVE frequency than 81% of tracked products
5.3
Avg CVSS
Higher Avg CVSS than 10% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Rsa Authentication Manager over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 13, 2012
14 years ago
Most Recent CVE
Apr 15, 2020
2,293 days ago

CVE Severity & Scoring

Rsa Authentication Manager25 CVEs
All CVEs352,719 CVEs
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network19 (76.0%)
Unknown6 (24.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low17 (68.0%)
High2 (8.0%)
Unknown6 (24.0%)
User Interaction
None5 (20.0%)
Unknown6 (24.0%)
Required14 (56.0%)
Privileges Required
Low3 (12.0%)
High7 (28.0%)
None9 (36.0%)
Unknown6 (24.0%)

Top CVEs

Signals from CVEs in this product scope (25 CVEs).

25 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
RSA Authentication Manager versions prior to 8.4 P1 contain an Insecure Credential Management Vulnerability. A malicious Operations Console administrator may be able to obtain the
Mar 13, 20197.225NONO
RSA Authentication Manager Security Console, versions 8.3 P1 and earlier, contains a reflected cross-site scripting vulnerability. A remote unauthenticated attacker could potential
Jun 21, 20186.122NONO
EMC RSA Authentication Manager 8.2 SP1 P4 and earlier contains a reflected cross-site scripting vulnerability that could potentially be exploited by malicious users to compromise t
Oct 31, 20176.122NONO
Cross-site scripting (XSS) vulnerability in EMC RSA Authentication Manager before 8.1 SP1 P14 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors
May 7, 20166.122NONO
RSA Authentication Manager versions prior to 8.4 P7 contain an XML Entity Injection Vulnerability. A remote authenticated malicious user could potentially exploit this vulnerabilit
Jan 3, 20206.521NONO
RSA Authentication Manager versions prior to 8.3 P3 are affected by a DOM-based cross-site scripting vulnerability which exists in its embedded MadCap Flare Help files. A remote un
Sep 28, 20186.121NONO
In EMC RSA Authentication Manager 8.2 SP1 Patch 1 and earlier, a malicious user logged into the Self-Service Console of RSA Authentication Manager as a target user can use a brute
Jul 17, 20175.921NONO
Open redirect vulnerability in EMC RSA Authentication Manager 8.x before 8.1 Patch 6 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks v
Dec 12, 20145.821NONO
RSA Authentication Manager versions prior to 8.4 P10 contain a stored cross-site scripting vulnerability in the Security Console. A malicious RSA Authentication Manager Security Co
Mar 26, 20204.820NONO
RSA Authentication Manager Operation Console, versions 8.3 P1 and earlier, contains a stored cross-site scripting vulnerability. A malicious Operations Console administrator could
Jun 21, 20186.120NONO

Exploit Exposure

Signals from CVEs in this product scope (25 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (25 CVEs).

Media Mentions

Signals from CVEs in this product scope (25 CVEs).

Top CNAs Publishing CVEs For Rsa Authentication Manager

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
8.465.10.7%00
8.345.41.5%00
8.224.71.3%00
8.126.01.5%00
8.035.01.2%00
7.164.71.0%00
7.035.21.1%00