CVE-2012-4614
Estado: ModificadaAlta (9.3)—
The default configuration of EMC Smarts Network Configuration Manager (NCM) before 9.1 does not require authentication for database access, which allows remote attackers to have an unspecified impact via a network session.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C
- Puntuación base: 9.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.28%
- Percentil entre todas las CVEs puntuadas: 83
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-287
Referencias
- http://archives.neohapsis.com/archives/bugtraq/2012-11/0095.html
- http://osvdb.org/87877
- http://secunia.com/advisories/51408
- http://www.securityfocus.com/bid/56682
- http://www.securitytracker.com/id?1027812
- http://archives.neohapsis.com/archives/bugtraq/2012-11/0095.html
- http://osvdb.org/87877
- http://secunia.com/advisories/51408
- http://www.securityfocus.com/bid/56682
- http://www.securitytracker.com/id?1027812
JSON original (NVD)
Mostrar
{
"id": "CVE-2012-4614",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 9.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "security_alert@emc.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2012-11-27T21:55:00.807",
"references": [
{
"url": "http://archives.neohapsis.com/archives/bugtraq/2012-11/0095.html",
"source": "security_alert@emc.com"
},
{
"url": "http://osvdb.org/87877",
"source": "security_alert@emc.com"
},
{
"url": "http://secunia.com/advisories/51408",
"source": "security_alert@emc.com"
},
{
"url": "http://www.securityfocus.com/bid/56682",
"source": "security_alert@emc.com"
},
{
"url": "http://www.securitytracker.com/id?1027812",
"source": "security_alert@emc.com"
},
{
"url": "http://archives.neohapsis.com/archives/bugtraq/2012-11/0095.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://osvdb.org/87877",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/51408",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/56682",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id?1027812",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-287"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The default configuration of EMC Smarts Network Configuration Manager (NCM) before 9.1 does not require authentication for database access, which allows remote attackers to have an unspecified impact via a network session."
},
{
"lang": "es",
"value": "La configuración por defecto de EMC Smarts Network Configuration Manager (NCM) antes de v9.1 no requiere de autenticación para el acceso a la base de datos, lo que permite a atacantes remotos tener un impacto no especificado a través de una sesión de red."
}
],
"lastModified": "2026-06-16T23:45:30.117",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:emc:it_operations_intelligence:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "118DDD22-D64F-41FA-8CA6-EEA002E579DB",
"versionEndIncluding": "9.0"
}
],
"operator": "OR"
}
]
}
],
"evaluatorComment": "Per: http://www.emc.com/it-management/smarts/index.htm\r\n\r\n\r\n\"EMC Smarts (previously IT Operations Intelligence 9.0)..\"\r\n\r\n",
"sourceIdentifier": "security_alert@emc.com"
}