Error handling in RSA Authentication Agent API and RSA Authentication Agent SDK - CVE-2017-14378

 

Error handling in RSA Authentication Agent API and RSA Authentication Agent SDK - CVE-2017-14378

Published: November 29, 2017


Vulnerability identifier: #VU9443
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-14378
CWE-ID: CWE-388
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication on the target system.

The weakness exists in RSA Authentication Agent for Web for Apache Web Server due to improper handling of return codes from the API/SDK. A remote attacker can trigger an error handling flaw and bypass authentication.


Affected software

RSA Authentication Agent API
RSA Authentication Agent SDK

How to mitigate CVE-2017-14378

Install update from vendor's website (API 8.5.1 for C, SDK 8.6.1 for C).


External References

Related Security Bulletins