« Volver al listado

CVE-2012-4615

Estado: ModificadaBaja (2.1)—

EMC Smarts Network Configuration Manager (NCM) before 9.1 uses a hardcoded encryption key for the storage of credentials, which allows local users to obtain sensitive information via unspecified vectors.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2012-4615",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 2.1,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "security_alert@emc.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2012-11-27T21:55:00.900",
  "references": [
    {
      "url": "http://archives.neohapsis.com/archives/bugtraq/2012-11/0095.html",
      "source": "security_alert@emc.com"
    },
    {
      "url": "http://osvdb.org/87878",
      "source": "security_alert@emc.com"
    },
    {
      "url": "http://packetstormsecurity.org/files/118358/EMC-Smarts-Network-Configuration-Manager-Bypass.html",
      "source": "security_alert@emc.com"
    },
    {
      "url": "http://secunia.com/advisories/51408",
      "source": "security_alert@emc.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/56682",
      "source": "security_alert@emc.com"
    },
    {
      "url": "http://www.securitytracker.com/id?1027812",
      "source": "security_alert@emc.com"
    },
    {
      "url": "http://archives.neohapsis.com/archives/bugtraq/2012-11/0095.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://osvdb.org/87878",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://packetstormsecurity.org/files/118358/EMC-Smarts-Network-Configuration-Manager-Bypass.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/51408",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/56682",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id?1027812",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-310"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "EMC Smarts Network Configuration Manager (NCM) before 9.1 uses a hardcoded encryption key for the storage of credentials, which allows local users to obtain sensitive information via unspecified vectors."
    },
    {
      "lang": "es",
      "value": "EMC Smarts Network Configuration Manager (NCM) antes de v9.1 tiene codificada la clave de cifrado para el almacenamiento de credenciales, lo que permite a usuarios remotos obtener información sensible a través de vectores no especificados."
    }
  ],
  "lastModified": "2026-06-16T23:45:30.217",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:emc:it_operations_intelligence:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "118DDD22-D64F-41FA-8CA6-EEA002E579DB",
              "versionEndIncluding": "9.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "evaluatorComment": "Per: http://www.emc.com/it-management/smarts/index.htm \"EMC Smarts (previously IT Operations Intelligence 9.0)...\"",
  "sourceIdentifier": "security_alert@emc.com"
}