Error handling in RSA Authentication Agent API and RSA Authentication Agent SDK - CVE-2017-14378
Published: November 29, 2017
Vulnerability identifier: #VU9443
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-14378
CWE-ID: CWE-388
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication on the target system.
The weakness exists in RSA Authentication Agent for Web for Apache Web Server due to improper handling of return codes from the API/SDK. A remote attacker can trigger an error handling flaw and bypass authentication.
Affected software
RSA Authentication Agent API
RSA Authentication Agent SDK
RSA Authentication Agent SDK
How to mitigate CVE-2017-14378
Install update from vendor's website (API 8.5.1 for C, SDK 8.6.1 for C).