cvedb.io
CVE-2018-1234
MEDIUM · CVSS 5.5
EPSS exploitation probability: 0%
Published 2018-03-30T21:29:01.807 · Last modified 2026-06-17T01:50:47.213

Summary

RSA Authentication Agent version 8.0.1 and earlier for Web for IIS is affected by a problem where access control list (ACL) permissions on a Windows Named Pipe were not sufficient to prevent access by unauthorized users. The attacker with local access to the system can exploit this vulnerability to read configuration properties for the authentication agent.

Affected products

rsa — authentication_agent_for_web

Does this affect you?

Add your gear to cvedb and we'll alert you only when rsa ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.