ZeroHour

CVE-2019-3758

CVSS 3.1
9.8 critical
EPSS
1%p72
Published
()
Modified
Description

RSA Archer, versions prior to 6.6 P2 (6.6.0.2), contain an improper authentication vulnerability. The vulnerability allows sysadmins to create user accounts with insufficient credentials. Unauthenticated attackers could gain unauthorized access to the system using those accounts.

Vendors
rsa
Products
archer
Weakness
CWE-288, CWE-521
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.