VulnerabilityModified
CVE-2008-6886
RSA EnVision 3.5.0, 3.5.1, 3.5.2, and 3.7.0 does not properly restrict access to unspecified user profile functionality, which allows remote attackers to obtain the administrator password hash and conduct brute force guessing attacks.
MEDIUM 5.0EPSS 1.49%
Does this matter?
Lower severity and a low EPSS score (1.49%). Track it; it rarely justifies an emergency change on its own.
Description
RSA EnVision 3.5.0, 3.5.1, 3.5.2, and 3.7.0 does not properly restrict access to unspecified user profile functionality, which allows remote attackers to obtain the administrator password hash and conduct brute force guessing attacks.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.49% probability · 73th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- rsa/envision
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=122765140110581&w=2Patch
- http://secunia.com/advisories/32883Vendor Advisory
- http://www.osvdb.org/50273
- http://www.secfault.org/?p=78Patch
- http://www.securityfocus.com/bid/32473
- http://www.vupen.com/english/advisories/2008/3288Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46884
- http://marc.info/?l=bugtraq&m=122765140110581&w=2Patch
- http://secunia.com/advisories/32883Vendor Advisory
- http://www.osvdb.org/50273
- http://www.secfault.org/?p=78Patch
- http://www.securityfocus.com/bid/32473
- http://www.vupen.com/english/advisories/2008/3288Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46884
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.