I-GEN opLYNX Central Authentication Bypass
Summary
| CVE | CVE-2012-4688 |
|---|---|
| State | PUBLISHED |
| Assigner | icscert |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-12-31 11:50:27 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The Central application in i-GEN opLYNX before 2.01.9 allows remote attackers to bypass authentication via vectors involving the disabling of browser JavaScript support. |
Risk And Classification
Primary CVSS: v2.0 7.5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:P
Problem Types: CWE-592 | CWE-287 | CWE-592 CWE-592
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 2.0 | [email protected] | Primary | 7.5 | AV:N/AC:L/Au:N/C:P/I:P/A:P | |
| 2.0 | [email protected] | Secondary | 7.5 | AV:N/AC:L/Au:N/C:P/I:P/A:P | |
| 2.0 | CNA | CVSS | 7.5 | AV:N/AC:L/Au:N/C:P/I:P/A:P |
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | I-GEN Solutions Corporation | OpLYNX | affected 2.01.8 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.cisa.gov/news-events/ics-advisories/icsa-12-362-01 | [email protected] | www.cisa.gov | |
| 404 - File Not Found | CISA | af854a3a-2127-422b-91ae-364da2661108 | www.us-cert.gov | US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Anthony Cicalla has identified an authentication bypass vulnerability (en)
Additional Advisory Data
Solutions
CNA: i-GEN Solutions has released a new version, opLYNX 2.01.9, that resolves this vulnerability. The new version is installed during logon and automatically applied. Anthony Cicalla has tested the new version and validated that it resolves the vulnerability. To manually obtain the new version, ICS-CERT recommends customers contact i-GEN Solutions customer service.i-GEN’s customer service, http://www.i-gen.com , [email protected]
There are currently no legacy QID mappings associated with this CVE.