CVE-2012-4571
Status: ModifiedLow (2.1)—
Python Keyring 0.9.1 does not securely initialize the cipher when encrypting passwords for CryptedFileKeyring files, which makes it easier for local users to obtain passwords via a brute-force attack.
CVSS
- Version: 2.0
- Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N
- Base score: 2.1
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.37%
- Percentile among all scored CVEs: 29
- Score date: 10/5/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-310
References
- http://pypi.python.org/pypi/keyring
- http://www.openwall.com/lists/oss-security/2012/10/31/8
- http://www.ubuntu.com/usn/USN-1634-1
- https://bugs.launchpad.net/ubuntu/+source/python-keyring/+bug/1004845
- http://pypi.python.org/pypi/keyring
- http://www.openwall.com/lists/oss-security/2012/10/31/8
- http://www.ubuntu.com/usn/USN-1634-1
- https://bugs.launchpad.net/ubuntu/+source/python-keyring/+bug/1004845
Raw JSON (NVD)
Show
{
"id": "CVE-2012-4571",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 2.1,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "secalert@redhat.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2012-11-30T22:55:01.830",
"references": [
{
"url": "http://pypi.python.org/pypi/keyring",
"source": "secalert@redhat.com"
},
{
"url": "http://www.openwall.com/lists/oss-security/2012/10/31/8",
"source": "secalert@redhat.com"
},
{
"url": "http://www.ubuntu.com/usn/USN-1634-1",
"source": "secalert@redhat.com"
},
{
"url": "https://bugs.launchpad.net/ubuntu/+source/python-keyring/+bug/1004845",
"source": "secalert@redhat.com"
},
{
"url": "http://pypi.python.org/pypi/keyring",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.openwall.com/lists/oss-security/2012/10/31/8",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.ubuntu.com/usn/USN-1634-1",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://bugs.launchpad.net/ubuntu/+source/python-keyring/+bug/1004845",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-310"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Python Keyring 0.9.1 does not securely initialize the cipher when encrypting passwords for CryptedFileKeyring files, which makes it easier for local users to obtain passwords via a brute-force attack."
},
{
"lang": "es",
"value": "Python Keyring v0.9.1 no inicializa de forma segura el sistema de cifrado para cifrar las contraseñas de los archivos CryptedFileKeyring, lo que hace que sea más fácil para los usuarios locales obtener contraseñas a través de un ataque de fuerza bruta."
}
],
"lastModified": "2026-06-16T23:45:25.253",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:python:keyring:0.9.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EBB3763D-3787-4E2C-8C12-7F907D4EB8E6"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "secalert@redhat.com"
}