« Volver al listado

CVE-2012-2605

Estado: ModificadaMedia (6.8)—

Multiple cross-site request forgery (CSRF) vulnerabilities in the administrative interface in Bradford Network Sentry before 5.3.3 allow remote attackers to hijack the authentication of administrators for requests that (1) insert XSS sequences or (2) send messages to clients.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2012-2605",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "cret@cert.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2012-06-13T15:55:01.337",
  "references": [
    {
      "url": "http://www.kb.cert.org/vuls/id/709939",
      "tags": [
        "US Government Resource"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/MAPG-8TJKAF",
      "tags": [
        "US Government Resource"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "https://na3.salesforce.com/sfc/#version?selectedDocumentId=06950000000IySO",
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/709939",
      "tags": [
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/MAPG-8TJKAF",
      "tags": [
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://na3.salesforce.com/sfc/#version?selectedDocumentId=06950000000IySO",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-352"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Multiple cross-site request forgery (CSRF) vulnerabilities in the administrative interface in Bradford Network Sentry before 5.3.3 allow remote attackers to hijack the authentication of administrators for requests that (1) insert XSS sequences or (2) send messages to clients."
    },
    {
      "lang": "es",
      "value": "Múltiples vulnerabilidades de falsificación de petición en sitios cruzados (CSRF) en el interfaz de administración de Bradford Network Sentry anteriores a 5.3.3. Permiten a usuarios remotos secuestrar (hijack) la autenticación de administradores para peticiones que (1) insertan secuencias XSS o (2) envían mensajes a clientes."
    }
  ],
  "lastModified": "2026-06-16T23:41:45.320",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:bradfordnetworks:network_sentry_appliance_software:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5EF852E8-8717-44E8-93E5-CCC5D5E3D698",
              "versionEndIncluding": "5.3"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:bradfordnetworks:network_sentry_appliance:ns500rx:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "33A75E86-3D97-4276-A281-D290F92E17E2"
            },
            {
              "criteria": "cpe:2.3:h:bradfordnetworks:network_sentry_appliance:ns500x:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E2331045-488B-4448-B8C4-641FD3E0483D"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cret@cert.org"
}