CVE-2021-41617 Security vulnerability for RSA Authentication Manager 8.6.x
Article Number
Applies To
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.6.x
Vulnerability : CVE-2021-41617: OpenSSH security vulnerability
CVE Identifier(s)
Link to Advisories
Alert Impact
Impacted - Apply RSA Remedy
Resolution
Upgrade to 8.7 P1
Addressed in SLES 12 SP5 for package openssh >= 7.2p2-78.13.1.
RSA Authentication Manager 8.7 P1 uses version 7.2p2-78.13.1 and so includes the fix for CVE-2021-41617.
Reference: https://www.suse.com/security/cve/CVE-2021-41617.html
Notes
Even without the fix, there is no impact from this issue since RSA Authentication Manager does not configure SSH in the manner required for the vulnerability to exist.
Also, remember that the SSH interface is not enabled by default and RSA recommends that customers DO NOT enable this interface unless required for maintenance and then disable it when maintenance is complete.
Disclaimer
Related Articles
Infineon Trusted Platform Module (TPM) Vulnerability (CVE-2017-15361) Impact on RSA Products 59Number of Views Spring-related vulnerabilities for RSA Authentication Manager 169Number of Views RSA Authentication Manager CVE-2016-0800 "DROWN" Vulnerability - False Positive 251Number of Views Apache vulnerability 'Apache HTTP Server mod_rewrite' from scan 50Number of Views Response to OpenSSH Vulnerabilities on RSA Authentication Manager 8.8 - CVE-2023-51385, CVE-2023-51767, CVE-2023-51384 106Number of Views
Trending Articles
RSA Authentication Manager 8.9 Setup and Configuration Guide How to 'Trust' the RSA Authentication Manager Security Console Self-Signed Root CA certificate and prevent Cert warnings. RSA Authentication Manager 8.9 Release Notes (January 2026) Configure RSA Authentication Manager as a Secure Proxy Server for Cloud Access Service RSA Authentication Manager Upgrade Process
Don't see what you're looking for?