Lucene search

K
cveIcscertCVE-2012-3018
HistoryJul 31, 2012 - 10:45 a.m.

CVE-2012-3018

2012-07-3110:45:42
CWE-310
icscert
web.nvd.nist.gov
23
iconics
genesis32
bizviz
security
lockout-recovery
encryption
authentication code
access restrictions
cve-2012-3018

CVSS2

4.4

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

AI Score

6.8

Confidence

Low

EPSS

0

Percentile

0.4%

The lockout-recovery feature in the Security Configurator component in ICONICS GENESIS32 9.22 and earlier and BizViz 9.22 and earlier uses an improper encryption algorithm for generation of an authentication code, which allows local users to bypass intended access restrictions and obtain administrative access by predicting a challenge response.

Affected configurations

Nvd
Node
iconicsgenesis32Range9.22
OR
iconicsgenesis32Match8.05
OR
iconicsgenesis32Match9.0
OR
iconicsgenesis32Match9.1
OR
iconicsgenesis32Match9.01
OR
iconicsgenesis32Match9.2
OR
iconicsgenesis32Match9.13
OR
iconicsgenesis32Match9.20
OR
iconicsgenesis32Match9.21
Node
iconicsbizvizRange9.22
OR
iconicsbizvizMatch8.05
OR
iconicsbizvizMatch9.0
OR
iconicsbizvizMatch9.01
OR
iconicsbizvizMatch9.1
OR
iconicsbizvizMatch9.2
OR
iconicsbizvizMatch9.13
OR
iconicsbizvizMatch9.20
OR
iconicsbizvizMatch9.21
VendorProductVersionCPE
iconicsgenesis32*cpe:2.3:a:iconics:genesis32:*:*:*:*:*:*:*:*
iconicsgenesis328.05cpe:2.3:a:iconics:genesis32:8.05:*:*:*:*:*:*:*
iconicsgenesis329.0cpe:2.3:a:iconics:genesis32:9.0:*:*:*:*:*:*:*
iconicsgenesis329.1cpe:2.3:a:iconics:genesis32:9.1:*:*:*:*:*:*:*
iconicsgenesis329.01cpe:2.3:a:iconics:genesis32:9.01:*:*:*:*:*:*:*
iconicsgenesis329.2cpe:2.3:a:iconics:genesis32:9.2:*:*:*:*:*:*:*
iconicsgenesis329.13cpe:2.3:a:iconics:genesis32:9.13:*:*:*:*:*:*:*
iconicsgenesis329.20cpe:2.3:a:iconics:genesis32:9.20:*:*:*:*:*:*:*
iconicsgenesis329.21cpe:2.3:a:iconics:genesis32:9.21:*:*:*:*:*:*:*
iconicsbizviz*cpe:2.3:a:iconics:bizviz:*:*:*:*:*:*:*:*
Rows per page:
1-10 of 181

CVSS2

4.4

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:P/I:P/A:P

AI Score

6.8

Confidence

Low

EPSS

0

Percentile

0.4%

Related for CVE-2012-3018