CVE-2014-0643: Emc Rsa Netwitness

High severity, CVSS 7.6. EPSS: 2.4% chance of exploitation in the next 30 days.

EMC RSA NetWitness before 9.8.5.19 and RSA Security Analytics before 10.2.4 and 10.3.x before 10.3.2, when Kerberos PAM is enabled, do not require a password, which allows remote attackers to bypass authentication by leveraging knowledge of a valid account name.

Affected products

  • Emc Rsa Netwitness: before 9.8.5.19 (fixed in 9.8.5.19)
  • Emc Rsa Security Analytics: from 10.2, before 10.2.4 (fixed in 10.2.4); from 10.3, before 10.3.2 (fixed in 10.3.2)

Published 2014-05-16. Last modified 2026-06-17.