CVE-2010-3321 | Date: (C)2010-10-07 (M)2023-12-22 |
RSA Authentication Client 2.0.x, 3.0, and 3.5.x before 3.5.3 does not properly handle a SENSITIVE or NON-EXTRACTABLE tag on a secret key object that is stored on a SecurID 800 authenticator, which allows local users to bypass intended access restrictions and read keys via unspecified PKCS#11 API requests.
CVSS Score and Metrics +CVSS Score and Metrics -CVSS V2 Severity: |
CVSS Score : 1.5 |
Exploit Score: 2.7 |
Impact Score: 2.9 |
|
CVSS V2 Metrics: |
Access Vector: LOCAL |
Access Complexity: MEDIUM |
Authentication: SINGLE |
Confidentiality: PARTIAL |
Integrity: NONE |
Availability: NONE |
| |