Description
EMC RSA Security SiteKey issues challenge-bypass tokens that persist forever without a cancellation interface for end users, which makes it easier for attackers to bypass one stage of authentication by stealing and replaying a token.
References (2)
Core 2
Core References
Various Sources x_refsource_misc
http://www.cr-labs.com/publications/WhySiteKey-20060824.pdf
Various Sources x_refsource_misc
http://www.cr-labs.com/publications/SiteKey-20060718.pdf
Scores
EPSS
0.0036
EPSS Percentile
58.6%
Details
Status
published
Products (1)
emc/rsa_security_sitekey
Published
Apr 30, 2007
Tracked Since
Feb 18, 2026