{"api_version":"1","generated_at":"2026-07-23T07:48:09+00:00","cve":"CVE-2019-3758","urls":{"html":"https://cve.report/CVE-2019-3758","api":"https://cve.report/api/cve/CVE-2019-3758.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-3758","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-3758"},"summary":{"title":"CVE-2019-3758","description":"RSA Archer, versions prior to 6.6 P2 (6.6.0.2), contain an improper authentication vulnerability. The vulnerability allows sysadmins to create user accounts with insufficient credentials. Unauthenticated attackers could gain unauthorized access to the system using those accounts.","state":"PUBLIC","assigner":"secure@dell.com","published_at":"2019-09-18 23:15:00","updated_at":"2020-10-16 14:14:00"},"problem_types":["CWE-521"],"metrics":[],"references":[{"url":"https://community.rsa.com/docs/DOC-106759","name":"https://community.rsa.com/docs/DOC-106759","refsource":"MISC","tags":["Vendor Advisory"],"title":"DSA-2019-127: RSA Archer Security Update for Mu... | RSA Link","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-3758","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-3758","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"3758","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"rsa","cpe5":"archer","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"3758","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"rsa","cpe5":"archer","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"secure@dell.com","DATE_PUBLIC":"2019-08-28","ID":"CVE-2019-3758","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Dell","product":{"product_data":[{"product_name":"RSA Archer","version":{"version_data":[{"version_value":"prior to 6.6 P2 (6.6.0.2)"}]}}]}}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"RSA Archer, versions prior to 6.6 P2 (6.6.0.2), contain an improper authentication vulnerability. The vulnerability allows sysadmins to create user accounts with insufficient credentials. Unauthenticated attackers could gain unauthorized access to the system using those accounts."}]},"impact":{"cvss":{"baseScore":8.1,"baseSeverity":"High","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.0"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-288: Authentication Bypass Using an Alternate Path or Channel"}]}]},"references":{"reference_data":[{"refsource":"MISC","url":"https://community.rsa.com/docs/DOC-106759","name":"https://community.rsa.com/docs/DOC-106759"}]}},"nvd":{"publishedDate":"2019-09-18 23:15:00","lastModifiedDate":"2020-10-16 14:14:00","problem_types":["CWE-521"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":7.5},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:rsa:archer:*:*:*:*:*:*:*:*","versionEndExcluding":"6.6.0.2","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"3758","Ordinal":"141367","Title":"CVE-2019-3758","CVE":"CVE-2019-3758","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"3758","Ordinal":"1","NoteData":"RSA Archer, versions prior to 6.6 P2 (6.6.0.2), contain an improper authentication vulnerability. The vulnerability allows sysadmins to create user accounts with insufficient credentials. Unauthenticated attackers could gain unauthorized access to the system using those accounts.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"3758","Ordinal":"2","NoteData":"2019-09-18","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"3758","Ordinal":"3","NoteData":"2020-08-31","Type":"Other","Title":"Modified"}]}}}