CVE-2012-4960
Last modified
CVE-2012-4960 is a vulnerability of currently unknown severity. The Huawei NE5000E, MA5200G, NE40E, NE80E, ATN, NE40, NE80, NE20E-X6, NE20, ME60, CX600, CX200, CX300, ACU, WLAN AC 6605, S9300, S7700, S2300, S3300, S5300, S3300HI, S5300HI, S5306, S6300, S2700, S3700, S5700, S6700, AR G3, H3C AR(OEM IN), AR 19, AR 29, AR 49, Eudemon100E, Eudemon200, Eudemon300, Eudemon500, Eudemon1000, Eudemon1000E-U/USG5300, Eudemon1000E-X/USG5500, Eudemon8080E/USG9300, Eudemon8160E/USG9300, Eudemon8000E-X/USG9500, E200E-C/USG2200, E200E-X3/USG2200, E200E-X5/USG2200, E200E-X7/USG2200, E200E-C/USG5100, E200E-X3/USG5100, E200E-X5/USG5100, E200E-X7/USG5100, E200E-B/USG2100, E200E-X1/USG2100, E200E-X2/USG2100, SVN5300, SVN2000, SVN5000, SVN3000, NIP100, NIP200, NIP1000, NIP2100, NIP2200, and NIP5100 use the DES algorithm for stored passwords, which makes it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack.. EPSS estimates a 3.45% chance of exploitation in the next 30 days.
Description
The Huawei NE5000E, MA5200G, NE40E, NE80E, ATN, NE40, NE80, NE20E-X6, NE20, ME60, CX600, CX200, CX300, ACU, WLAN AC 6605, S9300, S7700, S2300, S3300, S5300, S3300HI, S5300HI, S5306, S6300, S2700, S3700, S5700, S6700, AR G3, H3C AR(OEM IN), AR 19, AR 29, AR 49, Eudemon100E, Eudemon200, Eudemon300, Eudemon500, Eudemon1000, Eudemon1000E-U/USG5300, Eudemon1000E-X/USG5500, Eudemon8080E/USG9300, Eudemon8160E/USG9300, Eudemon8000E-X/USG9500, E200E-C/USG2200, E200E-X3/USG2200, E200E-X5/USG2200, E200E-X7/USG2200, E200E-C/USG5100, E200E-X3/USG5100, E200E-X5/USG5100, E200E-X7/USG5100, E200E-B/USG2100, E200E-X1/USG2100, E200E-X2/USG2100, SVN5300, SVN2000, SVN5000, SVN3000, NIP100, NIP200, NIP1000, NIP2100, NIP2200, and NIP5100 use the DES algorithm for stored passwords, which makes it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Acu | v100r003c01spc100 |
| Huawei | Acu | v200r001c00 |
| Huawei | Acu | v200r001c00spc100 |
| Huawei | Ar 19\/29\/49 | <= r2207 |
| Huawei | Ar G3 | v200r001c00 |
| Huawei | Ar G3 | v200r001c01 |
| Huawei | Ar G3 | v200r002c00spc200 |
| Huawei | Atn | v200r001c00 |
| Huawei | Atn | v200r001c01 |
| Huawei | Cx200 | v100r005 |
| Huawei | Cx300 | v100r005 |
| Huawei | Cx600 | v200r002 |
| Huawei | Cx600 | v600r001 |
| Huawei | Cx600 | v600r002 |
| Huawei | Cx600 | v600r003 |
| Huawei | E200 Usg2200 | <= v200r003c00 |
| Huawei | E200 Usg5100 | <= v200r003c00 |
| Huawei | E200e-B | <= v100r005c01 |
| Huawei | E200e-C | <= v200r003c00 |
| Huawei | E200e-Usg2100 | <= v100r005c01 |
| Huawei | E200e-X1 | <= v100r005c01 |
| Huawei | E200e-X2 | <= v100r005c01 |
| Huawei | E200x3 | <= v200r003c00 |
| Huawei | E200x5 | <= v200r003c00 |
| Huawei | E200x7 | <= v200r003c00 |
| Huawei | Eudemon 8080e | <= v100r003c00 |
| Huawei | Eudemon 8160e | <= v100r003c00 |
| Huawei | Eudemon Usg5300 | <= v200r001 |
| Huawei | Eudemon Usg5500 | <= v200r002 |
| Huawei | Eudemon Usg9300 | <= v100r003c00 |
| Huawei | Eudemon Usg9500 | <= v200r001c00spc600 |
| Huawei | Eudemon1000 | <= v200r006c02 |
| Huawei | Eudemon1000e-U | <= v200r001 |
| Huawei | Eudemon1000e-X | <= v200r002 |
| Huawei | Eudemon100e | v200r007 |
| Huawei | Eudemon200 | v200r001 |
| Huawei | Eudemon300 | <= v200r006c02 |
| Huawei | Eudemon500 | <= v200r006c02 |
| Huawei | Eudemon8000e-X | <= v200r001c00spc600 |
| Huawei | H3c Ar\(Oem In\) | <= r2209 |
| Huawei | Ma5200g | v200r003 |
| Huawei | Ma5200g | v300r003 |
| Huawei | Me60 | v100r005 |
| Huawei | Me60 | v100r006 |
| Huawei | Me60 | v600r002 |
| Huawei | Me60 | v600r003 |
| Huawei | Me60 | v600r005c00spc600 |
| Huawei | Ne20 | v200r005 |
| Huawei | Ne20e-X6 | v300r005 |
| Huawei | Ne40 | v300r005 |
Showing 50 of 107 affected configurations. See NVD for the full list.
References
- http://www.kb.cert.org/vuls/id/948096US Government Resource
- http://www.kb.cert.org/vuls/id/948096US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-4960?
How severe is CVE-2012-4960?
How do I fix CVE-2012-4960?
Are you affected by CVE-2012-4960?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
