CVE-2012-2287

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
25/09/2012
Last modified:
11/04/2025

Description

The authentication functionality in EMC RSA Authentication Agent 7.1 and RSA Authentication Client 3.5 on Windows XP and Windows Server 2003, when an unspecified configuration exists, allows remote authenticated users to bypass an intended token-authentication step, and establish a login session to a remote host, by leveraging Windows credentials for that host.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:emc:rsa_authentication_agent:7.1:*:*:*:*:*:*:*
cpe:2.3:a:emc:rsa_authentication_client:3.5:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2003:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:-:*:*:*:*:*:*:*