{"api_version":"1","generated_at":"2026-07-23T09:09:37+00:00","cve":"CVE-2012-2568","urls":{"html":"https://cve.report/CVE-2012-2568","api":"https://cve.report/api/cve/CVE-2012-2568.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2012-2568","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2012-2568"},"summary":{"title":"CVE-2012-2568","description":"d41d8cd98f00b204e9800998ecf8427e.php in the management web server on the Seagate BlackArmor device allows remote attackers to change the administrator password via unspecified vectors.","state":"PUBLISHED","assigner":"certcc","published_at":"2012-05-25 20:55:01","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-264","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"10","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.securityfocus.com/bid/53670","name":"http://www.securityfocus.com/bid/53670","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"BlackArmor Network Administrator Password Reset Security Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/75854","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/75854","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/49282","name":"http://secunia.com/advisories/49282","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"About Secunia Research | Flexera","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"http://www.kb.cert.org/vuls/id/515283","name":"http://www.kb.cert.org/vuls/id/515283","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"VU#515283 - Seagate BlackArmor device static administrator password reset vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2012-2568","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2012-2568","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2012","cve_id":"2568","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"seagate","cpe5":"blackarmor_nas","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[{"cvename":"CVE-2012-2568","organization":"Seagate","lastmodified":"2012-10-26","contributor":"","statementText":"The latest revision of the Seagate Software now includes a fix, which address the previously publicized security hole. We will be communicating this to our installed base of users both by direct email as well as Update notifications sent through the BlackArmor NAS User Interface. The software updates can be found here: http://www.seagate.com/support/external-hard-drives/network-storage/blackarmor-nas-110/banas-110-firmware-master-dl/ http://www.seagate.com/support/external-hard-drives/network-storage/blackarmor-nas-220/banas-220-firmware-master-dl/ http://www.seagate.com/support/external-hard-drives/network-storage/blackarmor-nas-440/banas-440-firmware-master-dl/ Note that there are 3 different versions of the firmware update, which correlate to the number of bays in the hardware (e.g 1-bay, 2-bay and 4-bay).","cve_year":"2012","cve_id":"2568","crc32":"d3d2da9d"}],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T19:34:25.947Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"53670","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/53670"},{"name":"blackarmor-network-sec-bypass(75854)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/75854"},{"name":"49282","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/49282"},{"name":"VU#515283","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/515283"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2012-05-23T00:00:00.000Z","descriptions":[{"lang":"en","value":"d41d8cd98f00b204e9800998ecf8427e.php in the management web server on the Seagate BlackArmor device allows remote attackers to change the administrator password via unspecified vectors."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-28T12:57:01.000Z","orgId":"37e5125f-f79b-445b-8fad-9564f167944b","shortName":"certcc"},"references":[{"name":"53670","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/53670"},{"name":"blackarmor-network-sec-bypass(75854)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/75854"},{"name":"49282","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/49282"},{"name":"VU#515283","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/515283"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cert@cert.org","ID":"CVE-2012-2568","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"d41d8cd98f00b204e9800998ecf8427e.php in the management web server on the Seagate BlackArmor device allows remote attackers to change the administrator password via unspecified vectors."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"53670","refsource":"BID","url":"http://www.securityfocus.com/bid/53670"},{"name":"blackarmor-network-sec-bypass(75854)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/75854"},{"name":"49282","refsource":"SECUNIA","url":"http://secunia.com/advisories/49282"},{"name":"VU#515283","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/515283"}]}}}},"cveMetadata":{"assignerOrgId":"37e5125f-f79b-445b-8fad-9564f167944b","assignerShortName":"certcc","cveId":"CVE-2012-2568","datePublished":"2012-05-25T20:00:00.000Z","dateReserved":"2012-05-09T00:00:00.000Z","dateUpdated":"2024-08-06T19:34:25.947Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2012-05-25 20:55:01","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-264","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:h:seagate:blackarmor_nas:*:*:*:*:*:*:*:*","matchCriteriaId":"2EB0AAF0-1AAE-42A4-B6B2-5A4C75D2F2EE"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2012","CveId":"2568","Ordinal":"1","Title":"CVE-2012-2568","CVE":"CVE-2012-2568","Year":"2012"},"notes":[{"CveYear":"2012","CveId":"2568","Ordinal":"1","NoteData":"d41d8cd98f00b204e9800998ecf8427e.php in the management web server on the Seagate BlackArmor device allows remote attackers to change the administrator password via unspecified vectors.","Type":"Description","Title":"CVE-2012-2568"},{"CveYear":"2012","CveId":"2568","Ordinal":"2","NoteData":"2012-05-25","Type":"Other","Title":"Published"},{"CveYear":"2012","CveId":"2568","Ordinal":"3","NoteData":"2017-08-28","Type":"Other","Title":"Modified"}]}}}