CVE-2024-12013
A CWE-1392 “Use of Default Credentials” was discovered affecting the 130.8005 TCP/IP Gateway running firmware version 12h. The device exposes an FTP server with default and easy-to-guess admin credentials. A remote attacker capable of interacting with the FTP server could gain access and perform changes over resources exposed by the service such as configuration files where password hashes are saved or where network settings are stored.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
- Puntuación base: 7.6
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.34%
- Percentil entre todas las CVEs puntuadas: 26
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1210Exploitation of Remote Serviceslateral movement85 % - Impacto principal
T1078.001Default Accountsstealth · persistence · privilege escalation · initial access90 % - Impacto secundario
T1556Modify Authentication Processdefense impairment · persistence · credential access70 % - Impacto secundario
T1565.001Stored Data Manipulationimpact75 %
Vector CVSS muestra PR:L (requiere privilegios remotos), acceso de red sin UI requerida, afectando a credenciales por defecto en FTP. Impactos: obtención de credenciales (T1078.001), modificación de configuración de hashes (T1565.001) y potencial manipulación de autenticación (T1556).
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-1392
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-12013",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-12013",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-02-13T16:53:11.220388Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "prodsec@nozominetworks.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.6,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 4.7,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "prodsec@nozominetworks.com",
"affectedData": [
{
"vendor": "Zettler",
"product": "130.8005",
"versions": [
{
"status": "affected",
"version": "12h",
"versionType": "semver"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2025-02-13T16:15:44.050",
"references": [
{
"url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-12013",
"source": "prodsec@nozominetworks.com"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "prodsec@nozominetworks.com",
"description": [
{
"lang": "en",
"value": "CWE-1392"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A CWE-1392 “Use of Default Credentials” was discovered affecting the 130.8005 TCP/IP Gateway running firmware version 12h. The device exposes an FTP server with default and easy-to-guess admin credentials. A remote attacker capable of interacting with the FTP server could gain access and perform changes over resources exposed by the service such as configuration files where password hashes are saved or where network settings are stored."
},
{
"lang": "es",
"value": "Se descubrió un error CWE-1392 “Uso de credenciales predeterminadas” que afectaba al gateway TCP/IP 130.8005 con la versión de firmware 12h. El dispositivo expone un servidor FTP con credenciales de administrador predeterminadas y fáciles de adivinar. Un atacante remoto capaz de interactuar con el servidor FTP podría obtener acceso y realizar cambios en los recursos expuestos por el servicio, como los archivos de configuración donde se guardan los hashes de contraseñas o donde se almacenan las configuraciones de red."
}
],
"lastModified": "2026-06-17T06:58:53.390",
"sourceIdentifier": "prodsec@nozominetworks.com"
}