« Back to list

CVE-2012-2964

Status: ModifiedMedium (5)—

The BreakingPoint Storm appliance before 3.0 requires cleartext credentials for establishing a session from a GUI administrative client, which allows remote attackers to obtain sensitive information by sniffing the network for XML documents.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (2)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2012-2964",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cret@cert.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2012-08-12T16:55:01.013",
  "references": [
    {
      "url": "http://www.kb.cert.org/vuls/id/520430",
      "tags": [
        "US Government Resource"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/MAPG-8GANCC",
      "tags": [
        "US Government Resource"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.secureworks.com/research/advisories/SWRX-2012-006/",
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/520430",
      "tags": [
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/MAPG-8GANCC",
      "tags": [
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.secureworks.com/research/advisories/SWRX-2012-006/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The BreakingPoint Storm appliance before 3.0 requires cleartext credentials for establishing a session from a GUI administrative client, which allows remote attackers to obtain sensitive information by sniffing the network for XML documents."
    },
    {
      "lang": "es",
      "value": "La aplicación BreakingPoint Storm v3.0 requiere credenciales en texto plano para el establecimiento de una sesión desde un cliente administrativo GUI, lo que permite a atacantes remotos obtener información sensible espiando el tráfico de red buscando documentos XML.\r\n"
    }
  ],
  "lastModified": "2026-06-16T23:42:26.107",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:breakingpointsystems:breakingpoint_storm_appliance_ctm:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0078011B-0E74-4B28-86B2-1846376EB92F",
              "versionEndIncluding": "2.0"
            },
            {
              "criteria": "cpe:2.3:o:breakingpointsystems:breakingpoint_storm_appliance_ctm:1.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1F67D0F6-DCDB-44A7-8D22-76F98651E4AF"
            },
            {
              "criteria": "cpe:2.3:o:breakingpointsystems:breakingpoint_storm_appliance_ctm:1.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "289B6569-1C90-424E-A9AB-487FAED24337"
            },
            {
              "criteria": "cpe:2.3:o:breakingpointsystems:breakingpoint_storm_appliance_ctm:1.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3AF5F962-C041-40E0-A63D-8805159062E8"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:breakingpointsystems:breakingpoint_storm_appliance:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E926FFE9-0B2F-4A4E-A3F1-ED8DE9CF74E6"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cret@cert.org"
}