CVE-2012-4613
Estado: ModificadaMedia (6.9)—
EMC RSA Data Protection Manager Appliance 2.7.x and 3.x before 3.2.1 does not properly restrict the number of authentication attempts by a user account, which makes it easier for local users to bypass intended access restrictions via a brute-force attack.
CVSS
- Versión: 2.0
- Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C
- Puntuación base: 6.9
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.33%
- Percentil entre todas las CVEs puntuadas: 25
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-287
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2012-4613",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.9,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:M/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.4,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "security_alert@emc.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2012-11-16T00:55:01.180",
"references": [
{
"url": "http://archives.neohapsis.com/archives/bugtraq/2012-11/0050.html",
"source": "security_alert@emc.com"
},
{
"url": "http://www.securityfocus.com/bid/56508",
"source": "security_alert@emc.com"
},
{
"url": "http://archives.neohapsis.com/archives/bugtraq/2012-11/0050.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/56508",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-287"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "EMC RSA Data Protection Manager Appliance 2.7.x and 3.x before 3.2.1 does not properly restrict the number of authentication attempts by a user account, which makes it easier for local users to bypass intended access restrictions via a brute-force attack."
},
{
"lang": "es",
"value": "EMC RSA Data Protection Manager Appliance v3.x y v2.7.x antes de v3.2.1 no restringe correctamente el número de intentos de autenticación de una cuenta de usuario, lo que hace que sea más fácil para los usuarios locales eludir restricciones de acceso por medio de un ataque de fuerza bruta.\r\n"
}
],
"lastModified": "2026-06-16T23:45:30.020",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:emc:rsa_data_protection_manager_appliance:2.7.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A4E90B05-EA3A-47B7-BF98-27DEC19740D8"
},
{
"criteria": "cpe:2.3:h:emc:rsa_data_protection_manager_appliance:3.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "24990883-A014-4E93-90A1-A36A52ACD967"
},
{
"criteria": "cpe:2.3:h:emc:rsa_data_protection_manager_appliance:3.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FC03AD04-84EE-4FD1-A85F-FBC346364D36"
},
{
"criteria": "cpe:2.3:h:emc:rsa_data_protection_manager_appliance:3.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1F178D3D-2CC7-4DAC-9059-53A472471954"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security_alert@emc.com"
}