Impact
A user with a role that allows action execution can reveal a sensitive RSA SecurID token serial number by running the enable or revoke token actions in the RSA SecurID Authentication Manager app for Splunk SOAR. The token_serial parameter is not marked as a password and is displayed in cleartext in the user interface, enabling unintended disclosure of sensitive token data. External parties cannot obtain the serial simply by observing the UI; the disclosure requires legitimate action‑run privileges, so the vulnerability is limited to authenticated users with action permissions.
Affected Systems
The affected product is the RSA SecurID Authentication Manager app for Splunk SOAR from Splunk. Versions below 1.0.5 of the app are vulnerable. The fix requires Splunk SOAR 8.6.0 or higher to run the fixed app version.
Risk and Exploitability
The CVSS score is 4.3, indicating moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Attackers need access to an account that can run actions, which is a valid but restricted attack vector. Once the proper action is triggered, the token serial is exposed in cleartext, potentially allowing further compromise of RSA SecurID authentication if the token serial is used elsewhere. Due to the required privileges, the risk is confined to organizations with internal users who can trigger these actions.
OpenCVE Enrichment