EMC RSA Authentication Agent 7.1.x before 7.1.2 on Windows does not enforce the Quick PIN Unlock timeout feature, which allows physically proximate attackers to bypass the passcode requirement for a screensaved session by entering a PIN after timeout expiration.
Weaknesses in this category are typically introduced during the configuration of the software.
Link | Tags |
---|---|
http://archives.neohapsis.com/archives/bugtraq/2013-03/0001.html | mailing list |