CVE-2012-5968
Estado: ModificadaMedia (4.8)—
The Huawei E585 device does not validate the status of admin sessions, which allows remote attackers to obtain sensitive user information and the session ID, and modify data, by leveraging access to the LAN network.
CVSS
- Versión: 2.0
- Vector: AV:A/AC:L/Au:N/C:P/I:P/A:N
- Puntuación base: 4.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.43%
- Percentil entre todas las CVEs puntuadas: 35
- Fecha de la puntuación: 3/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-20
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2012-5968",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.8,
"accessVector": "ADJACENT_NETWORK",
"vectorString": "AV:A/AC:L/Au:N/C:P/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 4.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 6.5,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cret@cert.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2012-12-19T11:55:59.750",
"references": [
{
"url": "http://www.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-198239.htm",
"tags": [
"Vendor Advisory"
],
"source": "cret@cert.org"
},
{
"url": "http://www.kb.cert.org/vuls/id/871148",
"tags": [
"US Government Resource"
],
"source": "cret@cert.org"
},
{
"url": "http://www.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-198239.htm",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.kb.cert.org/vuls/id/871148",
"tags": [
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The Huawei E585 device does not validate the status of admin sessions, which allows remote attackers to obtain sensitive user information and the session ID, and modify data, by leveraging access to the LAN network."
},
{
"lang": "es",
"value": "El dispositivo Huawei E585 no valida el estado de las sesiones de administración, lo que permite a atacantes remotos obtener información sensible del usuario y el ID de sesión y modificar datos, aprovechándose del acceso a la red inalámbrica.\r\n"
}
],
"lastModified": "2026-06-16T23:47:39.387",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:huawei:e585:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "22225E7E-2877-4BE9-A642-1A80A42DBA87"
},
{
"criteria": "cpe:2.3:h:huawei:e585u-82:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "985BF1C4-4154-452E-B362-E014E8EC67F8"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cret@cert.org"
}