CVE-2021-41617 Security vulnerability for RSA Authentication Manager 8.6.x
Article Number
Applies To
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.6.x
Vulnerability : CVE-2021-41617: OpenSSH security vulnerability
CVE Identifier(s)
Link to Advisories
Alert Impact
Impacted - Apply RSA Remedy
Resolution
Upgrade to 8.7 P1
Addressed in SLES 12 SP5 for package openssh >= 7.2p2-78.13.1.
RSA Authentication Manager 8.7 P1 uses version 7.2p2-78.13.1 and so includes the fix for CVE-2021-41617.
Reference: https://www.suse.com/security/cve/CVE-2021-41617.html
Notes
Even without the fix, there is no impact from this issue since RSA Authentication Manager does not configure SSH in the manner required for the vulnerability to exist.
Also, remember that the SSH interface is not enabled by default and RSA recommends that customers DO NOT enable this interface unless required for maintenance and then disable it when maintenance is complete.
Disclaimer
Related Articles
KCA Apache web server showing security vulnerability with scan due patch level/version 50Number of Views Spring-related vulnerabilities for RSA Authentication Manager 156Number of Views RSA-2024-08: RSA Governance and Lifecycle Critical Security Update for Unauthenticated JMX Agent and Older Version of Log4… 49Number of Views Bash bug Vulnerability (Shellshock) in RSA products 1.31KNumber of Views RSA ID Plus BlastRADIUS Vulnerability Fix: Frequently Asked Questions 295Number of Views
Trending Articles
RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide Troubleshooting RSA MFA Agent for Microsoft Windows Downloading RSA Authentication Manager license files or RSA Software token seed records RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory
Don't see what you're looking for?