Linux Kernel vulnerability CVE-2017-17806 on RSA Appliance
Originally Published: 2018-02-02
Article Number
Applies To
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.2 SP1
CVE Identifier(s)
Article Summary
The HMAC implementation (crypto/hmac.c) in the Linux kernel before 4.14.8 does not validate that the underlying cryptographic hash algorithm is unkeyed, allowing a local attacker able to use the AF_ALG-based hash interface (CONFIG_CRYPTO_USER_API_HASH) and the SHA-3 hash algorithm (CONFIG_CRYPTO_SHA3) to cause a kernel stack buffer overflow by executing a crafted sequence of system calls that encounter a missing SHA-3 initialization.
CVSS v3 Base Score: 7.8 High CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Alert Impact
Not Exploitable
Resolution
The RSA Authentication Manager appliance is a single-purpose, single-user “appliance” and NOT a general, multi-user system. This vulnerability requires that the attacker have local access to the system. The only user who can log in to the appliance is already capable of obtaining root privileges and so the flaw does not add additional risk.
Disclaimer
Related Articles
DSA-2019-062: RSA Authentication Manager Security Update for Linux Kernel Vulnerabilities 3Number of Views RSA Authentication Manager 8.x Linux Kernel Vulnerability (CVE-2017-2636) - False Positive 28Number of Views RSA Authentication Manager 8.2 SP1 Vulnerabilities in the Linux kernel – False Positive 4Number of Views Multiple Linux Kernel related vulnerabilities in Authentication Manager 8.1 SP1 P10 or later - False Positives 35Number of Views How do you merge FSM audit logs? 1Number of Views
Trending Articles
RSA Authentication Manager Upgrade Process RSA Release Notes for RSA Authentication Manager 8.8 RSA RADIUS Server service failed to start in the RSA Authentication Manager 8.1 Operations Console Microsoft Entra ID External MFA - Relying Party Configuration Using OIDC - RSA Ready Implementation Guide RSA Release Notes: Cloud Access Service and RSA Authenticators
Don't see what you're looking for?