SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2013-0931

EMC RSA Authentication Agent 7.1.x before 7.1.2 on Windows does not enforce the Quick PIN Unlock timeout feature, which allows physically proximate attackers to bypass the passcode requirement for a screensaved session by entering a PIN after timeout…

MEDIUM 5.4EPSS 0.55%

Does this matter?

Lower severity and a low EPSS score (0.55%). Track it; it rarely justifies an emergency change on its own.

Description

EMC RSA Authentication Agent 7.1.x before 7.1.2 on Windows does not enforce the Quick PIN Unlock timeout feature, which allows physically proximate attackers to bypass the passcode requirement for a screensaved session by entering a PIN after timeout expiration.

CVSS 2.0
5.4 MEDIUMAV:A/AC:M/Au:N/C:P/I:P/A:P
EPSS
0.55% probability · 44th percentile
CISA KEV
Not listed
Weakness
CWE-16
Affected
rsa/authentication agent for windows
Source
security_alert@emc.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.