Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Rsa

First CVE: Dec 1, 1999Active for: 27 yearsTotal CVEs: 115
25.3
VTI Score
Low

RSA maintains a focused portfolio of enterprise identity, governance, and risk-management products—principally its Archer platform, Authentication Manager, and Envision suite—that serve as critical infrastructure in large organizations' access-control and compliance workflows. Despite the narrow product range, this vendor ranks among the most prominent in the vulnerability landscape, reflecting the high value and broad deployment of its governance and authentication solutions. The vulnerability exposure recurs through application-layer weakness classes including cross-site scripting, authentication bypass, and sensitive-information disclosure, which are characteristic of web-facing identity and governance platforms. A moderate share of disclosures acquire public exploit availability, reflecting the appeal of identity systems as high-value attack targets. Defenders should treat RSA product advisories as priority items given their role in access-control enforcement; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
115
Total CVEs
More Total CVEs than 99% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
6.1
Avg CVSS Score
Higher Avg CVSS Score than 30% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Rsa over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 1, 1999
26 years ago
Most Recent CVE
Nov 24, 2025
242 days ago

Products(31 total)

Top CVEs

Signals from CVEs in this vendor scope (115 CVEs).

115 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2005-4734MEDIUM
Stack-based buffer overflow in IISWebAgentIF.dll in RSA Authentication Agent for Web (aka SecurID Web Agent) 5.2 and 5.3 for IIS allows remote attackers to execute arbitrary code v
Dec 31, 20056.464NOYES
CVE-2018-1247HIGH
RSA Authentication Manager Security Console, version 8.3 and earlier, contains a XML External Entity (XXE) vulnerability. This could potentially allow admin users to cause a denial
May 8, 20187.141NOYES
CVE-1999-0834HIGH
Buffer overflow in RSAREF2 via the encryption and decryption functions in the RSAREF library.
Dec 1, 199910.035NOYES
CVE-2024-47856CRITICAL
In RSA Authentication Agent before 7.4.7, service paths and shortcut paths may be vulnerable to path interception if the path has one or more spaces and is not surrounded by quotat
Nov 24, 20259.834NONO
CVE-2022-47529MEDIUM
Insecure Win32 memory objects in Endpoint Windows Agents in RSA NetWitness Platform before 12.2 allow local and admin Windows user accounts to modify the endpoint agent service con
Mar 28, 20236.732NOYES
CVE-2007-2417HIGH
Heap-based buffer overflow in _mprosrv.exe in Progress Software Progress 9.1E and OpenEdge 10.1x, as used by the RSA Authentication Manager 6.0 and 6.1, SecurID Appliance 2.0, ACE/
Jul 15, 200710.032NONO
CVE-2017-14377CRITICAL
EMC RSA Authentication Agent for Web: Apache Web Server version 8.0 and RSA Authentication Agent for Web: Apache Web Server version 8.0.1 prior to Build 618 have a security vulnera
Nov 29, 20179.831NONO
CVE-2019-3758CRITICAL
RSA Archer, versions prior to 6.6 P2 (6.6.0.2), contain an improper authentication vulnerability. The vulnerability allows sysadmins to create user accounts with insufficient crede
Sep 18, 20199.830NONO
CVE-2019-3725CRITICAL
RSA Netwitness Platform versions prior to 11.2.1.1 and RSA Security Analytics versions prior to 10.6.6.1 are vulnerable to a Command Injection vulnerability due to missing input va
May 15, 20199.830NONO
CVE-2022-30584HIGH
Archer Platform 6.3 before 6.11 (6.11.0.0) contains an Improper Access Control Vulnerability within SSO ADFS functionality that could potentially be exploited by malicious users to
May 26, 20228.828NONO
View all 115 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products115 CVEs
66%
25%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local12 (10.4%)
Network56 (48.7%)
Unknown47 (40.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low65 (56.5%)
High3 (2.6%)
Unknown47 (40.9%)
User Interaction
None37 (32.2%)
Unknown47 (40.9%)
Required31 (27.0%)
Privileges Required
Low36 (31.3%)
High7 (6.1%)
None25 (21.7%)
Unknown47 (40.9%)

Exploit Exposure

Signals from CVEs in this vendor scope (115 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
0.9% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
7 CVEs
6.1% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Rsa.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Rsa — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Rsa's Products

View all 2 CNAs →

Top CWEs