CVE-2012-3268

UnknownEPSS 2.26%

Last modified

CVE-2012-3268 is a vulnerability of currently unknown severity. Certain HP Access Controller, Fabric Module, Firewall, Router, Switch, and UTM Appliance products; certain HP 3Com Access Controller, Router, and Switch products; certain HP H3C Access Controller, Firewall, Router, Switch, and Switch and Route Processing Unit products; and certain Huawei Firewall/Gateway, Router, Switch, and Wireless products do not properly implement access control as defined in h3c-user.mib 2.0 and hh3c-user.mib 2.0, which allows remote authenticated users to discover credentials in UserInfoEntry values via an SNMP request with the read-only community.. EPSS estimates a 2.26% chance of exploitation in the next 30 days.

Description

Certain HP Access Controller, Fabric Module, Firewall, Router, Switch, and UTM Appliance products; certain HP 3Com Access Controller, Router, and Switch products; certain HP H3C Access Controller, Firewall, Router, Switch, and Switch and Route Processing Unit products; and certain Huawei Firewall/Gateway, Router, Switch, and Wireless products do not properly implement access control as defined in h3c-user.mib 2.0 and hh3c-user.mib 2.0, which allows remote authenticated users to discover credentials in UserInfoEntry values via an SNMP request with the read-only community.

Metrics

CVSS 3.0
/10
EPSS Probability
2.26%

80.7th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
Hp0150a129All versions
Hp0150a12aAll versions
Hp0150a12bAll versions
Hp0150a12cAll versions
Hp0231a0avAll versions
Hp0231a65tAll versions
Hp0231a761All versions
Hp0231a832All versions
Hp0231a86pAll versions
Hp0231a88aAll versions
Hp0231a88lAll versions
Hp0235a08fAll versions
Hp0235a08hAll versions
Hp0235a08kAll versions
Hp0235a08mAll versions
Hp0235a09tAll versions
Hp0235a0a7All versions
Hp0235a0a8All versions
Hp0235a0asAll versions
Hp0235a0bqAll versions
Hp0235a0brAll versions
Hp0235a0bsAll versions
Hp0235a0btAll versions
Hp0235a0buAll versions
Hp0235a0bxAll versions
Hp0235a0c0All versions
Hp0235a0c2All versions
Hp0235a0c4All versions
Hp0235a0ctAll versions
Hp0235a0e3All versions
Hp0235a0e5All versions
Hp0235a0e6All versions
Hp0235a0e7All versions
Hp0235a0g0All versions
Hp0235a0g1All versions
Hp0235a0g2All versions
Hp0235a0g3All versions
Hp0235a0g4All versions
Hp0235a0g5All versions
Hp0235a0g6All versions
Hp0235a0g7All versions
Hp0235a0g8All versions
Hp0235a0g9All versions
Hp0235a0gaAll versions
Hp0235a0gcAll versions
Hp0235a0gdAll versions
Hp0235a0geAll versions
Hp0235a0gfAll versions
Hp0235a10bAll versions
Hp0235a10cAll versions

Showing 50 of 687 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2012-3268?
Certain HP Access Controller, Fabric Module, Firewall, Router, Switch, and UTM Appliance products; certain HP 3Com Access Controller, Router, and Switch products; certain HP H3C Access Controller, Firewall, Router, Switch, and Switch and Route Processing Unit products; and certain Huawei Firewall/Gateway, Router, Switch, and Wireless products do not properly implement access control as defined in h3c-user.mib 2.0 and hh3c-user.mib 2.0, which allows remote authenticated users to discover credentials in UserInfoEntry values via an SNMP request with the read-only community.
How severe is CVE-2012-3268?
Severity scoring for CVE-2012-3268 is pending analysis. The EPSS model estimates a 2.26% probability of exploitation in the next 30 days.
How do I fix CVE-2012-3268?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2012-3268?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST