CVE-2019-3725
CRITICALRSA Netwitness < 11.2.1.1 and Security Analytics < 10.6.6.1 - Unauthenticated OS Command Injection
Title source: llmDescription
RSA Netwitness Platform versions prior to 11.2.1.1 and RSA Security Analytics versions prior to 10.6.6.1 are vulnerable to a Command Injection vulnerability due to missing input validation in the product. A remote unauthenticated malicious user could exploit this vulnerability to execute arbitrary commands on the server.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_confirm
https://community.rsa.com/docs/DOC-104202
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/108355
Scores
CVSS v3
9.8
EPSS
0.0283
EPSS Percentile
84.8%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-78
Status
published
Products (2)
rsa/netwitness
< 11.2.1.1
rsa/security_analytics
< 10.6.6.1
Published
May 15, 2019
Tracked Since
Feb 18, 2026