CVE-2018-1253
Estado: ModificadaMedia (6.1)—
RSA Authentication Manager Operation Console, versions 8.3 P1 and earlier, contains a stored cross-site scripting vulnerability. A malicious Operations Console administrator could potentially exploit this vulnerability to store arbitrary HTML or JavaScript code through the web interface. When other Operations Console administrators open the affected page, the injected scripts could potentially be executed in their browser.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Puntuación base: 6.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.48%
- Percentil entre todas las CVEs puntuadas: 73
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-79
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2018-1253",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
],
"cvssMetricV30": [
{
"type": "Secondary",
"source": "security_alert@emc.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.0",
"baseScore": 6.5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 3.7,
"exploitabilityScore": 2.3
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 6.1,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security_alert@emc.com",
"affectedData": [
{
"vendor": "RSA",
"product": "Authentication Manager",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "8.3 P1",
"versionType": "custom"
}
]
}
]
}
],
"published": "2018-06-21T15:29:00.270",
"references": [
{
"url": "http://seclists.org/fulldisclosure/2018/Jun/39",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "security_alert@emc.com"
},
{
"url": "http://www.securityfocus.com/bid/104534",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "security_alert@emc.com"
},
{
"url": "http://www.securitytracker.com/id/1041134",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "security_alert@emc.com"
},
{
"url": "http://seclists.org/fulldisclosure/2018/Jun/39",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/104534",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id/1041134",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "RSA Authentication Manager Operation Console, versions 8.3 P1 and earlier, contains a stored cross-site scripting vulnerability. A malicious Operations Console administrator could potentially exploit this vulnerability to store arbitrary HTML or JavaScript code through the web interface. When other Operations Console administrators open the affected page, the injected scripts could potentially be executed in their browser."
},
{
"lang": "es",
"value": "RSA Authentication Manager Operation Console, en versiones 8.3 P1 y anteriores, contiene una vulnerabilidad de Cross-Site Scripting (XSS) persistente. Un administrador de Operations Console podría explotar esta vulnerabilidad para almacenar código HTML o JavaScript arbitrario mediante la interfaz web. Cuando otros administradores Operations Console abren la página afectada, los scripts inyectados pueden ejecutarse en sus navegadores."
}
],
"lastModified": "2026-06-17T01:50:49.453",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:emc:rsa_authentication_manager:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F38C843F-4D75-4DC4-BCE2-AC94EA2AADFA",
"versionEndIncluding": "7.0"
},
{
"criteria": "cpe:2.3:a:emc:rsa_authentication_manager:7.1:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8DB84FE8-27E3-4B6A-9F7B-B3852FD973B2"
},
{
"criteria": "cpe:2.3:a:emc:rsa_authentication_manager:7.1:sp2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CFEA20F9-BFEA-4599-91B8-51F2C62257B1"
},
{
"criteria": "cpe:2.3:a:emc:rsa_authentication_manager:7.1:sp3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "276F775A-7622-46C1-AFAB-BAD4ADB4F551"
},
{
"criteria": "cpe:2.3:a:emc:rsa_authentication_manager:7.1:sp4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "28238983-F94B-4EC7-AE15-4E6B6110DC19"
},
{
"criteria": "cpe:2.3:a:emc:rsa_authentication_manager:8.0:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5D880442-0B4A-4D54-9E98-6091B59BC9F1"
},
{
"criteria": "cpe:2.3:a:emc:rsa_authentication_manager:8.0:p1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "008D1316-B493-42D2-8A28-FDB935B4DCE3"
},
{
"criteria": "cpe:2.3:a:emc:rsa_authentication_manager:8.1:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D5CEBCC8-C970-420B-9C32-2CD233461486"
},
{
"criteria": "cpe:2.3:a:emc:rsa_authentication_manager:8.1:sp1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AC7D1E9E-3BAE-4FD2-B69F-0013065F0744"
},
{
"criteria": "cpe:2.3:a:emc:rsa_authentication_manager:8.2:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0E662A19-3595-4E54-B6FA-C387E1B5FBA6"
},
{
"criteria": "cpe:2.3:a:emc:rsa_authentication_manager:8.2:sp1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7A3C063C-76E1-443A-8BAE-FFC9C66DE925"
},
{
"criteria": "cpe:2.3:a:emc:rsa_authentication_manager:8.3:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "29A8B165-32AE-42CC-BE85-CEEF25C8F27A"
},
{
"criteria": "cpe:2.3:a:emc:rsa_authentication_manager:8.3:p1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C55F4F6D-FFE4-4D14-9481-DC8D52B6EDFE"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security_alert@emc.com"
}