4.4

CVE-2012-3018

The lockout-recovery feature in the Security Configurator component in ICONICS GENESIS32 9.22 and earlier and BizViz 9.22 and earlier uses an improper encryption algorithm for generation of an authentication code, which allows local users to bypass intended access restrictions and obtain administrative access by predicting a challenge response.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IconicsGenesis32 Version <= 9.22
IconicsGenesis32 Version8.05
IconicsGenesis32 Version9.0
IconicsGenesis32 Version9.1
IconicsGenesis32 Version9.01
IconicsGenesis32 Version9.2
IconicsGenesis32 Version9.13
IconicsGenesis32 Version9.20
IconicsGenesis32 Version9.21
IconicsBizviz Version <= 9.22
IconicsBizviz Version8.05
IconicsBizviz Version9.0
IconicsBizviz Version9.01
IconicsBizviz Version9.1
IconicsBizviz Version9.2
IconicsBizviz Version9.13
IconicsBizviz Version9.20
IconicsBizviz Version9.21
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.03% 0.071
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.4 3.4 6.4
AV:L/AC:M/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.