← Back to browse · API

CVE-2019-3725

Severity
CRITICAL
CVSS
9.8
EPSS
0.02826
Risk score
40.19
CISA KEV
No
PoC
No
Published
2019-05-15
Modified
2024-09-16
First seen
2026-08-07
Aliases
EUVD-2019-13360, GHSA-P6HW-VXMG-57QG
Products
RSA:RSA Netwitness Platform unspecified ≤11.2.1.1, RSA:RSA Security Analytics RSA Security Analytics ≤10.6.6.1
Sources
euvd EUVD-2019-13360

Description

RSA Netwitness Platform versions prior to 11.2.1.1 and RSA Security Analytics versions prior to 10.6.6.1 are vulnerable to a Command Injection vulnerability due to missing input validation in the product. A remote unauthenticated malicious user could exploit this vulnerability to execute arbitrary commands on the server.

References