Show plain JSON{"id": "CVE-2013-0931", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 5.4, "accessVector": "ADJACENT_NETWORK", "vectorString": "AV:A/AC:M/Au:N/C:P/I:P/A:P", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "MEDIUM", "availabilityImpact": "PARTIAL", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 6.4, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 5.5, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}]}, "published": "2013-03-05T22:03:51.193", "references": [{"url": "http://archives.neohapsis.com/archives/bugtraq/2013-03/0001.html", "source": "security_alert@emc.com"}], "vulnStatus": "Analyzed", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-16"}]}], "descriptions": [{"lang": "en", "value": "EMC RSA Authentication Agent 7.1.x before 7.1.2 on Windows does not enforce the Quick PIN Unlock timeout feature, which allows physically proximate attackers to bypass the passcode requirement for a screensaved session by entering a PIN after timeout expiration."}, {"lang": "es", "value": "EMC RSA Authentication Agent v7.1.x anterior a v7.1.2 sobre Windows no refuerza la caracter\u00edstica Quick PIN Unlock, lo que permitir\u00eda a atacantes pr\u00f3ximos f\u00edsicamente evitar la restricci\u00f3n de c\u00f3digo de acceso cuando se inicia el protector de pantalla, introduciendo el PIN despu\u00e9s del tiempo de expiraci\u00f3n."}], "lastModified": "2013-03-06T05:00:00.000", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:rsa:authentication_agent_for_windows:7.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FE6A259E-ADAB-4FCB-A577-9E9FCA6B014E"}, {"criteria": "cpe:2.3:a:rsa:authentication_agent_for_windows:7.1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E5D1F6F3-948A-40CD-AEC7-11E3FE956DA4"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:microsoft:windows_2003_server:*:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "60EC86B8-5C8C-4873-B364-FB1F8EFE1CFF"}, {"criteria": "cpe:2.3:o:microsoft:windows_xp:*:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "E61F1C9B-44AF-4B35-A7B2-948EEF7639BD"}], "operator": "OR"}], "operator": "AND"}], "evaluatorComment": "Per http://archives.neohapsis.com/archives/bugtraq/2013-03/att-0001/ESA-2013-012.txt\r\n\"Affected Products:\r\n\r\nProduct: RSA Authentication Agent for Microsoft Windows version 7.1 and 7.1.1\r\n\r\nPlatforms: Windows XP and Windows 2003\"\r\n\r\n", "sourceIdentifier": "security_alert@emc.com"}