EMC Adaptive Authentication Out-Of-The-Box Authentication Security Bypass Vulnerability
BID:49183
Info
EMC Adaptive Authentication Out-Of-The-Box Authentication Security Bypass Vulnerability
| Bugtraq ID: | 49183 |
| Class: | Design Error |
| CVE: |
CVE-2011-2733 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 17 2011 12:00AM |
| Updated: | Aug 17 2011 12:00AM |
| Credit: | EMC |
| Vulnerable: |
EMC Adaptive Authentication 6.0.2.1 SP3 EMC Adaptive Authentication 6.0.2.1 SP2 Patch 1 EMC Adaptive Authentication 6.0.2.1 SP2 EMC Adaptive Authentication 6.0.2.1 SP1 Patch 2 EMC Adaptive Authentication 6.0.2.1 SP1 Patch 3 |
| Not Vulnerable: | |
Discussion
EMC Adaptive Authentication Out-Of-The-Box Authentication Security Bypass Vulnerability
EMC Adaptive Authentication is prone to a security-bypass vulnerability.
Successful exploits may allow attackers to hijack web sessions. Successful exploits will lead to further attacks.
The following versions of EMC Adaptive Authentication are vulnerable:
6.0.2.1 SP1 Patch 2 and SP1 Patch 3
6.0.2.1 SP2 and SP2 Patch 1
6.0.2.1 SP3
EMC Adaptive Authentication is prone to a security-bypass vulnerability.
Successful exploits may allow attackers to hijack web sessions. Successful exploits will lead to further attacks.
The following versions of EMC Adaptive Authentication are vulnerable:
6.0.2.1 SP1 Patch 2 and SP1 Patch 3
6.0.2.1 SP2 and SP2 Patch 1
6.0.2.1 SP3
Exploit / POC
EMC Adaptive Authentication Out-Of-The-Box Authentication Security Bypass Vulnerability
An attacker can carry out this attack using readily available network utilities.
An attacker can carry out this attack using readily available network utilities.
Solution / Fix
EMC Adaptive Authentication Out-Of-The-Box Authentication Security Bypass Vulnerability
Solution:
Vendor updates are available. Please contact the vendor for more information.
Solution:
Vendor updates are available. Please contact the vendor for more information.
References
EMC Adaptive Authentication Out-Of-The-Box Authentication Security Bypass Vulnerability
References:
References:
- Vendor Homepage (EMC )