« Volver al listado

CVE-2012-4613

Estado: ModificadaMedia (6.9)—

EMC RSA Data Protection Manager Appliance 2.7.x and 3.x before 3.2.1 does not properly restrict the number of authentication attempts by a user account, which makes it easier for local users to bypass intended access restrictions via a brute-force attack.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2012-4613",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.9,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:M/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.4,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "security_alert@emc.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2012-11-16T00:55:01.180",
  "references": [
    {
      "url": "http://archives.neohapsis.com/archives/bugtraq/2012-11/0050.html",
      "source": "security_alert@emc.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/56508",
      "source": "security_alert@emc.com"
    },
    {
      "url": "http://archives.neohapsis.com/archives/bugtraq/2012-11/0050.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/56508",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "EMC RSA Data Protection Manager Appliance 2.7.x and 3.x before 3.2.1 does not properly restrict the number of authentication attempts by a user account, which makes it easier for local users to bypass intended access restrictions via a brute-force attack."
    },
    {
      "lang": "es",
      "value": "EMC RSA Data Protection Manager Appliance v3.x y v2.7.x antes de v3.2.1 no restringe correctamente el número de intentos de autenticación de una cuenta de usuario, lo que hace que sea más fácil para los usuarios locales eludir restricciones de acceso por medio de un ataque de fuerza bruta.\r\n"
    }
  ],
  "lastModified": "2026-06-16T23:45:30.020",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:emc:rsa_data_protection_manager_appliance:2.7.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A4E90B05-EA3A-47B7-BF98-27DEC19740D8"
            },
            {
              "criteria": "cpe:2.3:h:emc:rsa_data_protection_manager_appliance:3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "24990883-A014-4E93-90A1-A36A52ACD967"
            },
            {
              "criteria": "cpe:2.3:h:emc:rsa_data_protection_manager_appliance:3.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FC03AD04-84EE-4FD1-A85F-FBC346364D36"
            },
            {
              "criteria": "cpe:2.3:h:emc:rsa_data_protection_manager_appliance:3.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1F178D3D-2CC7-4DAC-9059-53A472471954"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security_alert@emc.com"
}