« Volver al listado

CVE-2012-4614

Estado: ModificadaAlta (9.3)—

The default configuration of EMC Smarts Network Configuration Manager (NCM) before 9.1 does not require authentication for database access, which allows remote attackers to have an unspecified impact via a network session.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2012-4614",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 9.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "security_alert@emc.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2012-11-27T21:55:00.807",
  "references": [
    {
      "url": "http://archives.neohapsis.com/archives/bugtraq/2012-11/0095.html",
      "source": "security_alert@emc.com"
    },
    {
      "url": "http://osvdb.org/87877",
      "source": "security_alert@emc.com"
    },
    {
      "url": "http://secunia.com/advisories/51408",
      "source": "security_alert@emc.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/56682",
      "source": "security_alert@emc.com"
    },
    {
      "url": "http://www.securitytracker.com/id?1027812",
      "source": "security_alert@emc.com"
    },
    {
      "url": "http://archives.neohapsis.com/archives/bugtraq/2012-11/0095.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://osvdb.org/87877",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/51408",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/56682",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id?1027812",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The default configuration of EMC Smarts Network Configuration Manager (NCM) before 9.1 does not require authentication for database access, which allows remote attackers to have an unspecified impact via a network session."
    },
    {
      "lang": "es",
      "value": "La configuración por defecto de EMC Smarts Network Configuration Manager (NCM) antes de v9.1 no requiere de autenticación para el acceso a la base de datos, lo que permite a atacantes remotos tener un impacto no especificado a través de una sesión de red."
    }
  ],
  "lastModified": "2026-06-16T23:45:30.117",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:emc:it_operations_intelligence:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "118DDD22-D64F-41FA-8CA6-EEA002E579DB",
              "versionEndIncluding": "9.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "evaluatorComment": "Per: http://www.emc.com/it-management/smarts/index.htm\r\n\r\n\r\n\"EMC Smarts (previously IT Operations Intelligence 9.0)..\"\r\n\r\n",
  "sourceIdentifier": "security_alert@emc.com"
}