CVE-2021-41617 Security vulnerability for RSA Authentication Manager 8.6.x
Article Number
Applies To
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.6.x
Vulnerability : CVE-2021-41617: OpenSSH security vulnerability
CVE Identifier(s)
Link to Advisories
Alert Impact
Impacted - Apply RSA Remedy
Resolution
Upgrade to 8.7 P1
Addressed in SLES 12 SP5 for package openssh >= 7.2p2-78.13.1.
RSA Authentication Manager 8.7 P1 uses version 7.2p2-78.13.1 and so includes the fix for CVE-2021-41617.
Reference: https://www.suse.com/security/cve/CVE-2021-41617.html
Notes
Even without the fix, there is no impact from this issue since RSA Authentication Manager does not configure SSH in the manner required for the vulnerability to exist.
Also, remember that the SSH interface is not enabled by default and RSA recommends that customers DO NOT enable this interface unless required for maintenance and then disable it when maintenance is complete.
Disclaimer
Related Articles
Bash bug Vulnerability (Shellshock) in RSA products 1.3KNumber of Views RSA-2024-08: RSA Governance and Lifecycle Critical Security Update for Unauthenticated JMX Agent and Older Version of Log4… 45Number of Views RSA Customer Advisory: ClamAV Vulnerability CVE-2023-20032 CVE-2023-20052 88Number of Views CERT/CC Vulnerability Note VU#144389: Potential Impact on RSA Products 198Number of Views Best practices for running vulnerability scans against RSA Authentication Manager 8.x 1.07KNumber of Views
Trending Articles
RSA SecurID Software Token 5.0.2 for Windows Desktop displays message after reboot due to roaming profile: No token stor… RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA Release Notes: Cloud Access Service and RSA Authenticators RSA Authentication Manager Upgrade Process RSA Authentication Manager 8.9 Release Notes (January 2026)
Don't see what you're looking for?