Rsa Netwitness vulnerabilities
2 known vulnerabilities affecting rsa/netwitness.
Total CVEs
2
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2019-3725P2CRITICALCVSS 9.8fixed in 11.2.1.12019-05-15
CVE-2019-3725 [CRITICAL] CWE-78 CVE-2019-3725: RSA Netwitness Platform versions prior to 11.2.1.1 and RSA Security Analytics versions prior to 10.6
RSA Netwitness Platform versions prior to 11.2.1.1 and RSA Security Analytics versions prior to 10.6.6.1 are vulnerable to a Command Injection vulnerability due to missing input validation in the product. A remote unauthenticated malicious user could exploit this vulnerability to execute arbitrary commands on the server.
nvd
CVE-2022-47529P3MEDIUMCVSS 6.7PoCfixed in 12.22023-03-28
CVE-2022-47529 [MEDIUM] CVE-2022-47529: Insecure Win32 memory objects in Endpoint Windows Agents in RSA NetWitness Platform before 12.2 allo
Insecure Win32 memory objects in Endpoint Windows Agents in RSA NetWitness Platform before 12.2 allow local and admin Windows user accounts to modify the endpoint agent service configuration: to either disable it completely or run user-supplied code or commands, thereby bypassing tamper-protection features via ACL modification.
nvd