CoSoSys Endpoint Protector CVE-2012-2994 Predictable Password Generation Vulnerability
BID:55570
Info
CoSoSys Endpoint Protector CVE-2012-2994 Predictable Password Generation Vulnerability
| Bugtraq ID: | 55570 |
| Class: | Design Error |
| CVE: |
CVE-2012-2994 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 17 2012 12:00AM |
| Updated: | Sep 27 2012 08:10PM |
| Credit: | Christopher Campbell |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
CoSoSys Endpoint Protector CVE-2012-2994 Predictable Password Generation Vulnerability
CoSoSys Endpoint Protector is prone to an insecure password generation vulnerability.
Successfully exploiting this issue may allow an attacker to guess generated passwords and gain access to affected appliances.
CoSoSys Endpoint Protector 4 is vulnerable; other versions may also be affected.
CoSoSys Endpoint Protector is prone to an insecure password generation vulnerability.
Successfully exploiting this issue may allow an attacker to guess generated passwords and gain access to affected appliances.
CoSoSys Endpoint Protector 4 is vulnerable; other versions may also be affected.
Exploit / POC
CoSoSys Endpoint Protector CVE-2012-2994 Predictable Password Generation Vulnerability
An attacker can use readily available network utilities to exploit this issue.
An attacker can use readily available network utilities to exploit this issue.
Solution / Fix
CoSoSys Endpoint Protector CVE-2012-2994 Predictable Password Generation Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
CoSoSys Endpoint Protector CVE-2012-2994 Predictable Password Generation Vulnerability
References:
References: