Authentication Agent For Web
Vendor:
First CVE: Apr 14, 2005 · Active for 21 years
8
Total CVEs
More Total CVEs than 85% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
6.1
Avg CVSS
Higher Avg CVSS than 24% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Authentication Agent For Web over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 14, 2005
21 years ago
Most Recent CVE
Mar 30, 2018
3,038 days ago
CVE Severity & Scoring
Authentication Agent For Web8 CVEs
75%
13%
13%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (12.5%)
Network3 (37.5%)
Unknown4 (50.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (50.0%)
High0 (0.0%)
Unknown4 (50.0%)
User Interaction
None3 (37.5%)
Unknown4 (50.0%)
Required1 (12.5%)
Privileges Required
Low1 (12.5%)
High0 (0.0%)
None3 (37.5%)
Unknown4 (50.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-4734MEDIUM Stack-based buffer overflow in IISWebAgentIF.dll in RSA Authentication Agent for Web (aka SecurID Web Agent) 5.2 and 5.3 for IIS allows remote attackers to execute arbitrary code v | Dec 31, 2005 | 6.4 | 64 | NO | YES |
CVE-2017-14377CRITICAL EMC RSA Authentication Agent for Web: Apache Web Server version 8.0 and RSA Authentication Agent for Web: Apache Web Server version 8.0.1 prior to Build 618 have a security vulnera | Nov 29, 2017 | 9.8 | 31 | NO | NO |
CVE-2018-1232HIGH RSA Authentication Agent version 8.0.1 and earlier for Web for both IIS and Apache Web Server are impacted by a stack-based buffer overflow which may occur when handling certain ma | Mar 30, 2018 | 7.5 | 24 | NO | NO |
CVE-2005-3329MEDIUM Cross-site scripting (XSS) vulnerability in RSA Authentication Agent for Web 5.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the image parameter | Oct 27, 2005 | 4.3 | 21 | NO | YES |
CVE-2005-1118MEDIUM Cross-site scripting (XSS) vulnerability in IISWebAgentIF.dll in the RSA Authentication Agent for Web 5.2 allows remote attackers to inject arbitrary web script or HTML via the pos | Apr 14, 2005 | 4.3 | 21 | NO | YES |
CVE-2018-1234MEDIUM RSA Authentication Agent version 8.0.1 and earlier for Web for IIS is affected by a problem where access control list (ACL) permissions on a Windows Named Pipe were not sufficient | Mar 30, 2018 | 5.5 | 20 | NO | NO |
CVE-2018-1233MEDIUM RSA Authentication Agent version 8.0.1 and earlier for Web for both IIS and Apache Web Server are affected by a cross-site scripting vulnerability. The attackers could potentially | Mar 30, 2018 | 6.1 | 20 | NO | NO |
CVE-2010-3261MEDIUM Directory traversal vulnerability in RSA Authentication Agent 7.0 before P2 for Web allows remote attackers to read unspecified data via unknown vectors. | Sep 24, 2010 | 5.0 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
12.5% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
37.5% of CVEs· 91st percentile
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Authentication Agent For Web
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 8.0.1 | 1 | 9.8 | 3.0% | 0 | 0 |
| 8.0 | 1 | 9.8 | 3.0% | 0 | 0 |
| 5.3 | 2 | 5.7 | 28.1% | 0 | 1 |
| 5.2 | 4 | 5.0 | 15.2% | 0 | 3 |
| 5.1.1 | 2 | 4.7 | 1.9% | 0 | 1 |
| 5.1 | 2 | 4.7 | 1.9% | 0 | 1 |