Back
CVE-2017-14378
CRITICAL
EMC RSA Authentication Agent API 8.5 for C and RSA Authentication Agent SDK 8.6 for C allow attackers to bypass authentication, aka an "Error Handling Vulnerability."
Published: Nov 29, 2017
Modified: Jun 17, 2026
NVD-CWE-noinfo
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
CHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected Products (2)
| Vendor | Product | Version |
|---|---|---|
| emc | rsa_authentication_agent_api_for_c | 8.5 |
| emc | rsa_authentication_agent_sdk_for_c | 8.6 |
GitHub Security Advisory GHSA-w7qh-6j22-5xp3
EMC RSA Authentication Agent API 8.5 for C and RSA Authentication Agent SDK 8.6 for C allow...
References (6)
- http://seclists.org/fulldisclosure/2017/Nov/48 Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/101979 Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039877 Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2017/Nov/48 Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/101979 Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039877 Third Party Advisory, VDB Entry
Risk Scores
CVSS Score
10.0 / 10
EPSS Score
2.99%
Top 14% most likely to be exploited
Threat Score
40.9 / 100
Data Sources
NVD
EPSS
GitHub