This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject
  • RSA.com
  • Home
  • Advisories
    • SecurID
    • SecurID Governance & Lifecycle
  • Documentation
    • SecurID
      • Authentication Agents
        • API / SDK
        • Apache Web Server
        • Citrix StoreFront
        • IIS Web Server
        • MFA Agent for macOS
        • MFA Agent for Windows
        • Microsoft AD FS
        • Microsoft Windows
        • PAM
      • Authentication Engine
      • Authentication Manager
      • Cloud Authentication Service
      • Hardware Appliance
        Component Updates
      • Hardware Tokens
      • Integrations
      • SecurID App
      • SecurID Authenticator for macOS
      • SecurID SDK
      • Software Tokens
        • Android
        • iOS
        • macOS
        • Token Converter
        • Windows
    • SecurID Governance & Lifecycle
    • Technology Partners
  • Downloads
    • SecurID
      • Authentication Agents
        • API / SDK
        • Apache Web Server
        • Citrix StoreFront
        • IIS Web Server
        • MFA Agent for macOS
        • MFA Agent for Windows
        • Microsoft AD FS
        • Microsoft Windows
        • PAM
      • Authentication Engine
      • Authentication Manager
      • Cloud Authentication Service
      • Hardware Appliance
        Component Updates
      • Hardware Tokens
      • Integrations
      • SecurID Authenticator for macOS
      • Software Tokens
        • Android
        • iOS
        • macOS
        • Token Converter
        • Windows
    • SecurID Governance & Lifecycle
  • Community
    • SecurID
      • Blog
      • Discussions
      • Events
      • Idea Exchange
      • Knowledge Base
    • SecurID Governance & Lifecycle
      • Blog
      • Discussions
      • Events
      • Idea Exchange
      • Knowledge Base
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Ideas & Suggestions
      • Community Support Articles
      • Community Support Forum
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Education
    • Blog
    • Browse Courses
      • SecurID
      • SecurID Governance & Lifecycle
    • Certification Program
    • New Product Readiness
    • Student Resources
Sign In Register Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
Announcements

The email address for SecurID Community notifications is changing

View Details

Security Advisory Articles

  • SecurID Community
  • :
  • Support
  • :
  • Security Advisory Articles
  • :
  • Microprocessor Side-Channel Attacks (CVE-2017-5715, CVE-2017-5753, CVE-2017-5754): Impact on RSA pro...
  • Options
    • Subscribe to RSS Feed
    • Bookmark
    • Subscribe
    • Email to a Friend
    • Printer Friendly Page
    • Report Inappropriate Content
  • Mark as New
  • Bookmark
  • Subscribe
  • Mute
  • Subscribe to RSS Feed
  • Permalink
  • Print
  • Email to a Friend
  • Report Inappropriate Content

Microprocessor Side-Channel Attacks (CVE-2017-5715, CVE-2017-5753, CVE-2017-5754): Impact on RSA products

Article Number

000035890

CVE ID

000035890

Article Summary

RSA is aware of the new side-channel analysis attacks (also known as Meltdown and Spectre) affecting many modern microprocessors that were published by a team of security researchers on January 3, 2018. An unprivileged attacker with local user access to the system could potentially leverage these attacks to read privileged memory data that would otherwise be inaccessible.
  • Variant 1 (CVE-2017-5753, Spectre): Bounds check bypass
  • Variant 2 (CVE-2017-5715, also Spectre): Branch target injection
  • Variant 3 (CVE-2017-5754, Meltdown): Rogue data cache load

RSA has completed investigation of the impact of these issues on our products. This article will be updated with remediation steps as they become available for impacted products.

RSA recommends customers to follow security best practices for malware protection in general to protect against possible exploitation of these analysis methods until any future updates can be applied.

Link to Advisories

  • Intel Security Advisory: https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00088&languageid=en-fr
  • AMD Update: http://www.amd.com/en/corporate/speculative-execution
  • Microsoft Advisory: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV180002
  • Google Project Zero Blog Post: https://googleprojectzero.blogspot.com/2018/01/reading-privileged-memory-with-side.html
  • Research papers: https://meltdownattack.com

Resolution

 
RSA Product NameVersionsImpacted?DetailsLast Updated
3D Secure / Adaptive Authentication eCommerce Not ImpactedDirect access to RSA’s hosted devices and systems is granted only to administrative users who require it for the performance of their job functions. As a result, the reported issues do not introduce additional security risk to customer data hosted within the environment, and patches will be handled through the standard RSA vulnerability remediation process.2018-01-17
Access Manager6.2Not ImpactedIt is a software product only. Check with your hardware system vendor and operating system vendor for any available updates for the host system.2018-01-08
Adaptive Authentication Cloud Impacted - RemediatedWe have confirmed that our third party cloud platform provider has remediated the issue at the platform level. This remediation fully addresses the risk and requires no customer action. Direct access to RSA’s hosted devices and systems is granted only to administrative users who require it for the performance of their job functions. As a result, the reported issues do not introduce additional security risk at the OS level to customer data hosted within the environment, and OS level patches will be handled through the standard RSA vulnerability remediation process.2018-01-17
Adaptive Authentication Hosted Not ImpactedDirect access to RSA’s hosted devices and systems is granted only to administrative users who require it for the performance of their job functions. As a result, the reported issues do not introduce additional security risk to customer data hosted within the environment, and patches will be handled through the standard RSA vulnerability remediation process.2018-01-17
Adaptive Authentication On-PremAll SupportedNot ImpactedIt is a software product only. Check with your hardware system vendor and operating system vendor for any available updates for the host system.2018-01-10
Archer Hosted (US) Impacted - RemediatedWe have confirmed that our third party cloud platform provider has remediated the issue at the platform level. This remediation fully addresses the risk and requires no customer action. Direct access to RSA’s hosted devices and systems is granted only to administrative users who require it for the performance of their job functions. As a result, the reported issues do not introduce additional security risk at the OS level to customer data hosted within the environment, and OS level patches will be handled through the standard RSA vulnerability remediation process.2018-01-17
Archer Hosted (EMEA) Not ImpactedDirect access to RSA’s hosted devices and systems is granted only to administrative users who require it for the performance of their job functions. As a result, the reported issues do not introduce additional security risk to customer data hosted within the environment, and patches will be handled through the standard RSA vulnerability remediation process.2018-01-17
Archer PlatformAll SupportedNot ImpactedIt is a software product only. Check with your hardware system vendor and operating system vendor for any available updates for the host system.2018-01-08
Archer Security Operations Management (SecOps)All SupportedNot ImpactedIt is a software product only. Check with your hardware system vendor and operating system vendor for any available updates for the host system.2018-01-08
Archer Vulnerability & Risk Manager (VRM) - Hardware ApplianceAll SupportedNot ImpactedAs a single, root-user-only appliance, the reported issues do not introduce any additional security risk to a customer's environment because a root level user already has full access to all information on the system. Customers should follow the recommended best practices to protect the access of highly privileged accounts. For guidance on updating your RSA Archer VRM Hardware Appliance with the latest OS and BIOS firmware updates, refer to KB article 000036320.2018-05-15
Archer Vulnerability & Risk Manager (VRM) - Virtual ApplianceAll SupportedNot ImpactedIt is a single-user, root-user-only virtual appliance. The reported issues do not introduce any additional security risk to a customer's environment for "in-guest" attacks, provided the recommended best practices to protect the access of highly privileged accounts are followed. Check with your hardware system vendor and hypervisor vendor for any available updates for the host system to prevent "guest-to-host" and "guest-to-guest" attacks. For guidance on applying OS patches to your RSA Archer VRM Virtual Appliance, refer to KB article 000036184.2018-05-15
Authentication Manager (Hardware Appliance - Dell PowerEdge & Intel platforms)All SupportedNot ImpactedIt is a single-user, root-user-only appliance. The reported issues do not introduce any additional security risk to a customer's environment, provided the recommended best practices to protect the access of highly privileged accounts are followed.2018-01-10
Authentication Manager (Virtual Appliance)All SupportedNot ImpactedIt is a single-user, root-user-only virtual appliance. The reported issues do not introduce any additional security risk to a customer's environment for "in-guest" attacks, provided the recommended best practices to protect the access of highly privileged accounts are followed. Check with your hardware system vendor and hypervisor vendor for any available updates for the host system to prevent "guest-to-host" and "guest-to-guest" attacks.2018-01-10
Authentication Manager Web TierAll SupportedNot ImpactedIt is a software product only. Check with your hardware system vendor and operating system vendor for any available updates for the host system.2018-01-11
BSAFE C Products: MES, Crypto-C ME, SSL-CAll SupportedNot ImpactedIt is a software product only. Check with your hardware system vendor and operating system vendor for any available updates for the host system.2018-01-09
BSAFE Java Products: Cert-J, Crypto-J, SSL-JAll SupportedNot ImpactedIt is a software product only. Check with your hardware system vendor and operating system vendor for any available updates for the host system.2018-01-09
Data Loss Prevention (Hardware Appliance)9.6.x, 9.5.xImpacted - RemediatedRefer to the security advisory DSA-2018-163.2018-09-11
Data Loss Prevention (Virtual Appliance)9.6.x, 9.5.xImpacted - RemediatedCheck with your hardware system vendor and hypervisor vendor for any available updates for the host system to prevent "guest-to-host" and "guest-to-guest" attacks. Refer to the security advisory DSA-2018-163 for updating guest operating system to prevent "in-guest" attacks.2018-09-11
Data Protection Manager (Software)All SupportedNot ImpactedIt is a software product only. Check with your hardware system vendor and operating system vendor for any available updates for the host system.2018-01-08
Data Protection Manager (Hardware Appliance)All SupportedImpacted - RemediatedRSA Data Protection Manager 3.5.2.6.1 contains resolution for this issue. For more details, refer to the security advisory DSA-2018-078.2018-05-31
Data Protection Manager (Virtual Appliance)All SupportedImpacted - RemediatedCheck with your hardware system vendor and hypervisor vendor for any available updates for the host system to prevent "guest-to-host" and "guest-to-guest" attacks. RSA Data Protection Manager 3.5.2.6.1 contains resolution for this issue. For more details, refer to the security advisory DSA-2018-078.2018-05-31
DCS: Certificate Manager6.9Not ImpactedIt is a software product only. Check with your hardware system vendor and operating system vendor for any available updates for the host system.2018-01-09
DCS: Validation Manager3.2Not ImpactedIt is a software product only. Check with your hardware system vendor and operating system vendor for any available updates for the host system.2018-01-09
eFraudNetwork (eFN) Not ImpactedDirect access to RSA’s hosted devices and systems is granted only to administrative users who require it for the performance of their job functions. As a result, the reported issues do not introduce additional security risk to customer data hosted within the environment, and patches will be handled through the standard RSA vulnerability remediation process.2018-01-17
enVisionEOL The product has reached End of Life. Please refer to the Product Version Life Cycle for RSA enVision page on RSA Link.2018-01-11
Federated Identity Manager4.2Not ImpactedIt is a software product only. Check with your hardware system vendor and operating system vendor for any available updates for the host system.2018-01-08
FraudAction (OTMS) Not ImpactedDirect access to RSA’s hosted devices and systems is granted only to administrative users who require it for the performance of their job functions. As a result, the reported issues do not introduce additional security risk to customer data hosted within the environment, and patches will be handled through the standard RSA vulnerability remediation process.2018-01-17
Identity Governance and Lifecycle (Software),
Via Lifecycle and Governance (Software),
Identity Management & Governance (Software)
7.0.2, 7.0.1, 7.0, 6.9.1, 6.9.0Not ImpactedIt is a software product only. Check with your hardware system vendor and operating system vendor for any available updates for the host system.2018-01-08
Identity Governance & Lifecycle (Hardware Appliance),
Via Lifecycle & Governance (Hardware Appliance),
Identity Management & Governance (Hardware Appliance)
7.0.2, 7.0.1, 7.0, 6.9.1, 6.9.0ImpactedRemediation plan is in progress. An appliance updater with OS updates and a security advisory on applying the BIOS fix will be made available (target date: TBD).

Any Remote Agents or Remote AFX deployed in customer environment are a software product only and are not impacted. Check with your hardware system vendor and operating system vendor for any available updates for the host system.
2018-01-24
Identity Governance and Lifecycle SaaS / MyAccessLive Impacted - RemediatedWe have confirmed that our third party cloud platform provider has remediated the issue at the platform level. This remediation fully addresses the risk and requires no customer action. Direct access to RSA’s hosted devices and systems is granted only to administrative users who require it for the performance of their job functions. As a result, the reported issues do not introduce additional security risk at the OS level to customer data hosted within the environment, and OS level patches will be handled through the standard RSA vulnerability remediation process.

Any Remote Agents or Remote AFX deployed in customer environment are a software product only and are not impacted. Check with your hardware system vendor and operating system vendor for any available updates for the host system.
2018-01-15
NetWitness Endpoint (ECAT)All SupportedNot ImpactedIt is a software product only. Check with your hardware system vendor and operating system vendor for any available updates for the host system.2018-01-08
NetWitness Logs & Packets / Security Analytics
(Hardware Appliance)
All SupportedNot ImpactedAs a single, root-user-only appliance, the reported issues do not introduce any additional security risk to a customer's environment because a root level user already has full access to all information on the system. Customers should follow the recommended best practices to protect the access of highly privileged accounts. The BIOS/OS updates will be incorporated to the product release as part of the regular patching process (current target date is February, 2018).2018-01-17
NetWitness Logs & Packets / Security Analytics
(Virtual Appliance)
All SupportedNot ImpactedIt is a single-user, root-user-only virtual appliance. The reported issues do not introduce any additional security risk to a customer's environment for "in-guest" attacks, provided the recommended best practices to protect the access of highly privileged accounts are followed. Check with your hardware system vendor and hypervisor vendor for any available updates for the host system to prevent "guest-to-host" and "guest-to-guest" attacks.2018-01-11
NetWitness Logs & Packets / Security Analytics - Legacy Windows CollectorAll SupportedNot ImpactedIt is a software product only. Check with your hardware system vendor and operating system vendor for any available updates for the host system.2018-01-10
NetWitness Live Infrastructure Not ImpactedDirect access to RSA’s hosted devices and systems is granted only to administrative users who require it for the performance of their job functions. As a result, the reported issues do not introduce additional security risk to customer data hosted within the environment, and patches will be handled through the standard RSA vulnerability remediation process.2018-01-17
RSA Authentication Client (RAC)All SupportedNot ImpactedIt is a software product only. Check with your hardware system vendor and operating system vendor for any available updates for the host system.2018-01-10
RSA Central Not ImpactedDirect access to RSA’s hosted devices and systems is granted only to administrative users who require it for the performance of their job functions. As a result, the reported issues do not introduce additional security risk to customer data hosted within the environment, and patches will be handled through the standard RSA vulnerability remediation process.2018-01-17
SecurID Access Cloud ServiceAll SupportedImpacted - RemediatedWe have confirmed that our third party cloud platform provider has remediated the issue at the platform level. This remediation fully addresses the risk and requires no customer action. Direct access to RSA’s hosted devices and systems is granted only to administrative users who require it for the performance of their job functions. As a result, the reported issues do not introduce additional security risk at the OS level to customer data hosted within the environment, and OS level patches will be handled through the standard RSA vulnerability remediation process.2018-01-15
SecurID Access IDR VMAll SupportedNot ImpactedAccess to the virtual appliance OS to load external code is restricted to highly privileged accounts only. The reported issues do not introduce any additional security risk to a customer's environment for potential "in-guest" attacks, provided the recommended best practices to protect the access of highly privileged accounts are followed. Check with your hardware system vendor and hypervisor vendor for any available updates for the host system to prevent "guest-to-host" and "guest-to-guest" attacks.2018-01-15
SecurID Agent for PAMAll SupportedNot ImpactedIt is a software product only. Check with your hardware system vendor and operating system vendor for any available updates for the host system.2018-01-09
SecurID Agent for WebAll SupportedNot ImpactedIt is a software product only. Check with your hardware system vendor and operating system vendor for any available updates for the host system.2018-01-09
SecurID Agent for WindowsAll SupportedNot ImpactedIt is a software product only. Check with your hardware system vendor and operating system vendor for any available updates for the host system.2018-01-09
SecurID Authenticate App for AndroidAll SupportedNot ImpactedIt is a software product only. Check with your hardware system vendor and operating system vendor for any available updates for the host system.2018-01-11
SecurID Authenticate App for iOSAll SupportedNot ImpactedIt is a software product only. Check with your hardware system vendor and operating system vendor for any available updates for the host system.2018-01-11
SecurID Authenticate App for Windows 10All SupportedNot ImpactedIt is a software product only. Check with your hardware system vendor and operating system vendor for any available updates for the host system.2018-01-11
SecurID Authentication EngineAll SupportedNot ImpactedIt is a software product only. Check with your hardware system vendor and operating system vendor for any available updates for the host system.2018-01-09
SecurID Authentication SDKAll SupportedNot ImpactedIt is a software product only. Check with your hardware system vendor and operating system vendor for any available updates for the host system.2018-01-09
SecurID Software Token ConverterAll SupportedNot ImpactedIt is a software product only. Check with your hardware system vendor and operating system vendor for any available updates for the host system.2018-01-09
SecurID Software Token for AndroidAll SupportedNot ImpactedIt is a software product only. Check with your hardware system vendor and operating system vendor for any available updates for the host system.2018-01-09
SecurID Software Token for BlackberryAll SupportedNot ImpactedIt is a software product only. Check with your hardware system vendor and operating system vendor for any available updates for the host system.2018-01-09
SecurID Software Token for DesktopAll SupportedNot ImpactedIt is a software product only. Check with your hardware system vendor and operating system vendor for any available updates for the host system.2018-01-09
SecurID Software Token for iPhoneAll SupportedNot ImpactedIt is a software product only. Check with your hardware system vendor and operating system vendor for any available updates for the host system.2018-01-09
SecurID Software Token for Windows MobileAll SupportedNot ImpactedIt is a software product only. Check with your hardware system vendor and operating system vendor for any available updates for the host system.2018-01-09
SecurID Software Token ToolbarAll SupportedNot ImpactedIt is a software product only. Check with your hardware system vendor and operating system vendor for any available updates for the host system.2018-01-09
SecurID Software Token Web SDKAll SupportedNot ImpactedIt is a software product only. Check with your hardware system vendor and operating system vendor for any available updates for the host system.2018-01-09
SecurID Transaction Signing SDKAll SupportedNot ImpactedIt is a software product only. Check with your hardware system vendor and operating system vendor for any available updates for the host system.2018-01-09
SYN Impacted - RemediatedWe have confirmed that our third party cloud platform provider has remediated the issue at the platform level. This remediation fully addresses the risk and requires no customer action. Direct access to RSA’s hosted devices and systems is granted only to administrative users who require it for the performance of their job functions. As a result, the reported issues do not introduce additional security risk at the OS level to customer data hosted within the environment, and OS level patches will be handled through the standard RSA vulnerability remediation process.2018-01-17
Web Threat DetectionAll SupportedNot ImpactedIt is a software product only. Check with your hardware system vendor and operating system vendor for any available updates for the host system.2018-01-10

Notes

For information regarding the impact on other Dell products refer to the following knowledge base articles:
  • Dell EMC: https://support.emc.com/kb/516117
  • Dell Client: http://www.dell.com/support/article/SLN308587
  • Dell Enterprise (Dell Servers, Storage, and Networking): http://www.dell.com/support/article/SLN308588
  • Dell EMC CPSD: http://support.vce.com/kA2A0000000PHXB
Tags (26)
  • Advisory
  • All Products
  • All RSA Products
  • Customer Support
  • Customer Support Article
  • CVE
  • High Profile
  • Impact
  • Impacted
  • KB Article
  • Knowledge Article
  • Knowledge Base
  • Recommendation
  • RSA Security Advisory
  • RSA Security Alert
  • Security Advisory
  • Security Advisory Article
  • Security Alert
  • Security Notification
  • Security Recommendations
  • Security Warning
  • Vuln
  • Vulnerabilities
  • Vulnerability
  • Vulnerability Warning
  • Vulnerable
0 Likes
Was this article helpful? Yes No
Share
No ratings
Version history
Last update:
‎2020-12-12 07:53 PM
Updated by:
Administrator RSA-KB-Sync Administrator

Related Content

Article Dashboard
  • Article History
Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • Customer Success
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Provide Feedback
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.