CVE-2014-4631

RSA Adaptive Authentication (On-Premise) 6.0.2.1 through 7.1 P3, when using device binding in a Challenge SOAP call or using the RSA Adaptive Authentication Integration Adapters with Out-of-Band Phone (Authentify) functionality, conducts permanent device binding even when authentication fails, which allows remote attackers to bypass authentication.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:P/A:N
dellCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 76%
VendorProductVersion
emcrsa_adaptive_authentication_on-premise
6.0.2.1
emcrsa_adaptive_authentication_on-premise
6.0.2.1:sp1_patch2
emcrsa_adaptive_authentication_on-premise
6.0.2.1:sp1_patch3
emcrsa_adaptive_authentication_on-premise
6.0.2.1:sp2
emcrsa_adaptive_authentication_on-premise
6.0.2.1:sp2_patch1
emcrsa_adaptive_authentication_on-premise
6.0.2.1:sp3
emcrsa_adaptive_authentication_on-premise
6.0.2.1:sp3_p3
emcrsa_adaptive_authentication_on-premise
7.0
emcrsa_adaptive_authentication_on-premise
7.1
emcrsa_adaptive_authentication_on-premise
7.1:p2
𝑥
= Vulnerable software versions