RSA Authentication Manager 8.2 False Positive Security Vulnerabilities
3 years ago
Originally Published: 2017-04-20
Article Number
000064257
Applies To
RSA Product Set: SecurID
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.2
CVE Identifier(s)
CVE-2016-9311,CVE-2016-9131,CVE-2016-9147,CVE-2016-9444,CVE-2016-2119,CVE-2016-2123,CVE-2015-5146,CVE-2015-5194,CVE-2015-5219,CVE-2015-5300
Article Summary
This article provides a list of security vulnerabilities that cannot be exploited on RSA Authentication Manager 8.2, but which may be flagged by security scanners.
Alert Impact
Not Exploitable
Resolution
The vulnerabilities listed in the table below are in order by the date on which RSA Authentication Manager Engineering determined that the Authentication Manager 8.2 was not vulnerable.
Embedded ComponentCVE IDSummary of VulnerabilityReason why Product is not VulnerableDate Determined False Positive
ntpCVE-2016-9311CVE-2016-9311Response: The flaw exists but cannot be exploited.14-Apr-17
  
ntpd in NTP before 4.2.8p9, when the trap service is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted packet.AM does not enable the trap service.
  
CVSS v3 Base Score: 5.9 Medium 
ISC BINDCVE-2016-9131CVE-2016-9131Response: The flaw does not exist14-Apr-17
  
named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x before 9.11.0-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed response to an RTYPE ANY query.ISC BIND is not used in the RSA Authentication Manager 8.2 appliance.
ISC BINDCVE-2016-9147CVE-2016-9147Response: The flaw does not exist14-Apr-17
  
named in ISC BIND 9.9.9-P4, 9.9.9-S6, 9.10.4-P4, and 9.11.0-P1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a response containing an inconsistency among the DNSSEC-related RRsets.ISC BIND is not used in the RSA Authentication Manager 8.2 appliance.
ISC BINDCVE-2016-9444CVE-2016-9444Response: The flaw does not exist14-Apr-17
  
named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x before 9.11.0-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted DS resource record in an answer.ISC BIND is not used in the RSA Authentication Manager 8.2 appliance.
smbCVE-2016-2119CVE-2016-2119Response: The flaw does not exist14-Apr-17
  
libcli/smb/smbXcli_base.c in Samba 4.x before 4.2.14, 4.3.x before 4.3.11, and 4.4.x before 4.4.5 allows man-in-the-middle attackers to bypass a client-signing protection mechanism, and consequently spoof SMB2 and SMB3 servers, via the (1) SMB2_SESSION_FLAG_IS_GUEST or (2) SMB2_SESSION_FLAG_IS_NULL flag.This issue is not present in the version of the application used in the RSA Authentication Manager appliance.
  
CVSS v3 Base Score: 7.5 High 
smbCVE-2016-2123CVE-2016-2123Response: The flaw does not exist14-Apr-17
  
The Samba routine ndr_pull_dnsp_name contains an integer wrap problem, leading to an attacker-controlled memory overwrite. ndr_pull_dnsp_name parses data from the Samba Active Directory ldb database. Any user who can write to the dnsRecord attribute over LDAP can trigger this memory corruption.This issue is not present in the version of the application used in the RSA Authentication Manager appliance.
  
By default, all authenticated LDAP users can write to the dnsRecord attribute on new DNS objects. This makes the defect a remote privilege escalation. 
  
CVSS v3 Base Score: 8.1 High (from Red Hat) 
ntpCVE-2015-5146CVE-2015-5146Response: The flaw exists but is not exploitable.19-Apr-17
  
Under limited and specific circumstances an attacker can send a crafted packet to cause a vulnerable ntpd instance to crash. This requires each of the following to be true:ntpd is not configured to allow remote configuration on the RSA Authentication Manager appliance.
  
ntpd set up to allow for remote configuration (not allowed by default), and 
  
knowledge of the configuration password, and 
  
access to a computer entrusted to perform remote configuration. 
  
CVSS v2 Base Score: 1.45 Low (from SUSE) 
ntpCVE-2015-5194CVE-2015-5194Response: The flaw does not exist.19-Apr-17
  
It was discovered that sntp would hang in an infinite loop when a crafted NTP packet was received, related to the conversion of the precision value in the packet to double.SLES 11.4 does not have this issue.
ntpCVE-2015-5219CVE-2015-5219Response: The flaw exists but is not exploitable.19-Apr-17
  
It was discovered that sntp would hang in an infinite loop when a crafted NTP packet was received, related to the conversion of the precision value in the packet to double.The sntp client is present but not used.
  
CVSS v2 Base Score: 4.0 Medium (from Red Hat) 
ntpCVE-2015-5300CVE-2015-5300Response: The flaw does not exist.19-Apr-17
  
If ntpd is always started with the -g option, which is common and against long-standing recommendation, and if at the moment ntpd is restarted an attacker can immediately respond to enough requests from enough sources trusted by the target, which is difficult and not common, there is a window of opportunity where the attacker can cause ntpd to set the time to an arbitrary value. Similarly, if an attacker is able to respond to enough requests from enough sources trusted by the target, the attacker can cause ntpd to abort and restart, at which point it can tell the target to set the time to an arbitrary value if and only if ntpd was re-started against long-standing recommendation with the -g flag, or if ntpd was not given the -g flag, the attacker can move the target system's time by at most 900 seconds' time per attack.The RSA Authentication Manager appliance v8.2.0.4 already includes this fix
  
CVSS v3 Base Score: 4.0 Medium (from NTP.org) 
Disclaimer
Read and use the information in this RSA Security Advisory to assist in avoiding any situation that might arise from the problems described herein. If you have any questions regarding this product alert, contact RSA Software Technical Support at 1- 800 995 5095. RSA Security LLC and its affiliates, including without limitation, its ultimate parent company, EMC Corporation, distributes RSA Security Advisories in order to bring to the attention of users of the affected RSA products, important security information. RSA recommends that all users determine the applicability of this information to their individual situations and take appropriate action. The information set forth herein is provided 'as is' without warranty of any kind. RSA disclaims all warranties, either express or implied, including the warranties of merchantability, fitness for a particular purpose, title and non-infringement. In no event, shall RSA, its affiliates or suppliers, be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if RSA, its affiliates or suppliers have been advised of the possibility of such damages. Some jurisdictions do not allow the exclusion or limitation of liability for consequential or incidental damages, so the foregoing limitation may not apply.