CVE-2014-0643

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
16/05/2014
Last modified:
12/04/2025

Description

EMC RSA NetWitness before 9.8.5.19 and RSA Security Analytics before 10.2.4 and 10.3.x before 10.3.2, when Kerberos PAM is enabled, do not require a password, which allows remote attackers to bypass authentication by leveraging knowledge of a valid account name.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:emc:rsa_netwitness:*:*:*:*:*:*:*:* 9.8.5.19 (excluding)
cpe:2.3:a:emc:rsa_security_analytics:*:*:*:*:*:*:*:* 10.2 (including) 10.2.4 (excluding)
cpe:2.3:a:emc:rsa_security_analytics:*:*:*:*:*:*:*:* 10.3 (including) 10.3.2 (excluding)