CVE Vulnerabilities

CVE-2010-3321

Published: Oct 07, 2010 | Modified: Oct 10, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
1.5 LOW
AV:L/AC:M/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

RSA Authentication Client 2.0.x, 3.0, and 3.5.x before 3.5.3 does not properly handle a SENSITIVE or NON-EXTRACTABLE tag on a secret key object that is stored on a SecurID 800 authenticator, which allows local users to bypass intended access restrictions and read keys via unspecified PKCS#11 API requests.

Affected Software

Name Vendor Start Version End Version
Authentication_client Rsa 2.0 (including) 2.0 (including)
Authentication_client Rsa 3.0 (including) 3.0 (including)
Authentication_client Rsa 3.5.1 (including) 3.5.1 (including)

References