CVE-2012-2280
Summary
| CVE | CVE-2012-2280 |
|---|---|
| State | PUBLISHED |
| Assigner | dell |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-07-13 21:55:02 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | EMC RSA Authentication Manager 7.1 before SP4 P14 and RSA SecurID Appliance 3.0 before SP4 P14 do not properly use frames, which allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to a "Cross frame scripting vulnerability." |
Risk And Classification
Primary CVSS: v2.0 5 from [email protected]
AV:N/AC:L/Au:N/C:N/I:P/A:N
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:L/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Emc | Rsa Authentication Manager | 7.0 | All | All | All |
| Application | Emc | Rsa Authentication Manager | 7.1 | All | All | All |
| Application | Emc | Rsa Authentication Manager | 7.1 | sp3 | All | All |
| Application | Emc | Rsa Authentication Manager | All | sp4 | All | All |
| Application | Rsa | Authentication Manager | 7.1 | sp42 | All | All |
| Application | Rsa | Securid Appliance | 2.0 | All | All | All |
| Application | Rsa | Securid Appliance | 2.0.1 | All | All | All |
| Application | Rsa | Securid Appliance | 2.0.2 | All | All | All |
| Application | Rsa | Securid Appliance | 3.0 | All | All | All |
| Application | Rsa | Securid Appliance | 3.0 | sp2 | All | All |
| Application | Rsa | Securid Appliance | 3.0 | sp3 | All | All |
| Application | Rsa | Securid Appliance | 3.0 | sp4 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| archives.neohapsis.com/archives/bugtraq/2012-07/0064.html | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.