CVE-2012-3018
Summary
| CVE | CVE-2012-3018 |
|---|---|
| State | PUBLISHED |
| Assigner | icscert |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-07-31 10:45:42 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The lockout-recovery feature in the Security Configurator component in ICONICS GENESIS32 9.22 and earlier and BizViz 9.22 and earlier uses an improper encryption algorithm for generation of an authentication code, which allows local users to bypass intended access restrictions and obtain administrative access by predicting a challenge response. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:L/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Iconics | Bizviz | 8.05 | All | All | All |
| Application | Iconics | Bizviz | 9.0 | All | All | All |
| Application | Iconics | Bizviz | 9.01 | All | All | All |
| Application | Iconics | Bizviz | 9.1 | All | All | All |
| Application | Iconics | Bizviz | 9.13 | All | All | All |
| Application | Iconics | Bizviz | 9.2 | All | All | All |
| Application | Iconics | Bizviz | 9.20 | All | All | All |
| Application | Iconics | Bizviz | 9.21 | All | All | All |
| Application | Iconics | Bizviz | All | All | All | All |
| Application | Iconics | Genesis32 | 8.05 | All | All | All |
| Application | Iconics | Genesis32 | 9.0 | All | All | All |
| Application | Iconics | Genesis32 | 9.01 | All | All | All |
| Application | Iconics | Genesis32 | 9.1 | All | All | All |
| Application | Iconics | Genesis32 | 9.13 | All | All | All |
| Application | Iconics | Genesis32 | 9.2 | All | All | All |
| Application | Iconics | Genesis32 | 9.20 | All | All | All |
| Application | Iconics | Genesis32 | 9.21 | All | All | All |
| Application | Iconics | Genesis32 | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 404 - File Not Found | CISA | af854a3a-2127-422b-91ae-364da2661108 | www.us-cert.gov | US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.