CVE-2012-2280
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
13/07/2012
Last modified:
11/04/2025
Description
EMC RSA Authentication Manager 7.1 before SP4 P14 and RSA SecurID Appliance 3.0 before SP4 P14 do not properly use frames, which allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to a "Cross frame scripting vulnerability."
Impact
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:emc:rsa_authentication_manager:*:sp4:*:*:*:*:*:* | 7.1 (including) | |
cpe:2.3:a:emc:rsa_authentication_manager:7.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:emc:rsa_authentication_manager:7.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:emc:rsa_authentication_manager:7.1:sp3:*:*:*:*:*:* | ||
cpe:2.3:a:rsa:authentication_manager:7.1:sp42:*:*:*:*:*:* | ||
cpe:2.3:a:rsa:securid_appliance:2.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:rsa:securid_appliance:2.0.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:rsa:securid_appliance:2.0.2:*:*:*:*:*:*:* | ||
cpe:2.3:a:rsa:securid_appliance:3.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:rsa:securid_appliance:3.0:sp2:*:*:*:*:*:* | ||
cpe:2.3:a:rsa:securid_appliance:3.0:sp3:*:*:*:*:*:* | ||
cpe:2.3:a:rsa:securid_appliance:3.0:sp4:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page