« Volver al listado

CVE-2012-4899

Estado: ModificadaBaja (2.1)—

WellinTech KingView 6.5.3 and earlier uses a weak password-hashing algorithm, which makes it easier for local users to discover credentials by reading an unspecified file.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2012-4899",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 2.1,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2012-10-10T18:55:05.550",
  "references": [
    {
      "url": "http://www.us-cert.gov/control_systems/pdf/ICSA-12-283-02.pdf",
      "tags": [
        "US Government Resource"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.wellintech.com/index.php/news/33-patch-for-kingview653",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.us-cert.gov/control_systems/pdf/ICSA-12-283-02.pdf",
      "tags": [
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.wellintech.com/index.php/news/33-patch-for-kingview653",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-310"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "WellinTech KingView 6.5.3 and earlier uses a weak password-hashing algorithm, which makes it easier for local users to discover credentials by reading an unspecified file."
    },
    {
      "lang": "es",
      "value": "WellinTech KingView6.5.3 y anterior utiliza algoritmo débil de generación de contraseñas, lo que hace que sea más fácil para los usuarios locales descubrir credenciales mediante la lectura de un archivo especificado."
    }
  ],
  "lastModified": "2026-06-16T23:45:52.287",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:wellintech:kingview:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "39B19F35-84B4-45AE-96D9-352213070CBC",
              "versionEndIncluding": "6.53"
            },
            {
              "criteria": "cpe:2.3:a:wellintech:kingview:3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DAB5609B-2D1E-42F5-9C78-1460A21C8795"
            },
            {
              "criteria": "cpe:2.3:a:wellintech:kingview:6.5.30.2010.18018:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F98B1909-52F3-42C7-AF6B-FE5EC1FB1657"
            },
            {
              "criteria": "cpe:2.3:a:wellintech:kingview:6.52:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "37C00AAD-8824-4F27-8203-EBBDB879772D"
            },
            {
              "criteria": "cpe:2.3:a:wellintech:kingview:65.30.2010.18018:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1DAAC197-9039-4D12-A4B0-7A534E3A1B59"
            },
            {
              "criteria": "cpe:2.3:a:wellintech:kingview:65.30.17249:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5161BBEA-1BA5-4FF1-9D8A-52D6C7BE2282"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}