Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2012-4587

Опубликовано: 22 авг. 2012
Источник: nvd
CVSS2: 3.5
EPSS Низкий

Описание

McAfee Enterprise Mobility Manager (EMM) Agent before 4.8 and Server before 10.1, when one-time provisioning (OTP) mode is enabled, have an improper dependency on DNS SRV records, which makes it easier for remote attackers to discover user passwords by spoofing the EMM server, as demonstrated by a password entered on an iOS device.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:mcafee:enterprise_mobility_manager:*:*:*:*:*:*:*:*
Версия до 4.7 (включая)
cpe:2.3:a:mcafee:enterprise_mobility_manager_agent:*:*:*:*:*:*:*:*
Версия до 10.0 (включая)

EPSS

Процентиль: 39%
0.00176
Низкий

3.5 Low

CVSS2

Дефекты

CWE-264

Связанные уязвимости

github
больше 3 лет назад

McAfee Enterprise Mobility Manager (EMM) Agent before 4.8 and Server before 10.1, when one-time provisioning (OTP) mode is enabled, have an improper dependency on DNS SRV records, which makes it easier for remote attackers to discover user passwords by spoofing the EMM server, as demonstrated by a password entered on an iOS device.

EPSS

Процентиль: 39%
0.00176
Низкий

3.5 Low

CVSS2

Дефекты

CWE-264