← Back

CVE-2014-0643

nvd nist
Published: May 16, 2014Modified: May 6, 2026

JSON object

Loading...
7.6
Vector
AV:N/AC:H/Au:N/C:C/I:C/A:C
Exploitability: 4.9 / Impact: 10.0
Source: NVD

Description

EMC RSA NetWitness before 9.8.5.19 and RSA Security Analytics before 10.2.4 and 10.3.x before 10.3.2, when Kerberos PAM is enabled, do not require a password, which allows remote attackers to bypass authentication by leveraging knowledge of a valid account name.

Affected (3)

2 products
Rsa Netwitness
Rsa Security Analytics
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Before 9.8.5.19
Emc
From 10.2 to 10.2.4
From 10.3 to 10.3.2

References (2)

Source: security_alert@emc.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.