CVE-2013-0941

low Apache
CVSS v3 Base Score
2.1
AV:L/AC:L/Au:N/C:P/I:N/A:N
EPSS Score
0.0%
Exploitation probability in 30 days
Top 88% most likely to be exploited
Attack Characteristics
Attack Vector
Local
Attack Complexity
Low
Confidentiality
P
Integrity
None
Availability
None
Published: May 22, 2013 (4740 days ago)
Last Modified: April 29, 2026
Vendor: Apache
Source: NVD

Description

EMC RSA Authentication API before 8.1 SP1, RSA Web Agent before 5.3.5 for Apache Web Server, RSA Web Agent before 5.3.5 for IIS, RSA PAM Agent before 7.0, and RSA Agent before 6.1.4 for Microsoft Windows use an improper encryption algorithm and a weak key for maintaining the stored data of the node secret for the SecurID Authentication API, which allows local users to obtain sensitive information via cryptographic attacks on this data.

CWE

CWE-310

Affected Products

rsa authentication apirsa securid web agentrsa pluggable authentication module agentrsa authentication agent

References