VulnerabilityModified
CVE-2012-2284
The (1) install and (2) upgrade processes in EMC NetWorker Module for Microsoft Applications (NMM) 2.2.1, 2.3 before build 122, and 2.4 before build 375, when Exchange Server is used, allow local users to read cleartext administrator credentials via…
LOW 2.1EPSS 0.33%
Does this matter?
Lower severity and a low EPSS score (0.33%). Track it; it rarely justifies an emergency change on its own.
Description
The (1) install and (2) upgrade processes in EMC NetWorker Module for Microsoft Applications (NMM) 2.2.1, 2.3 before build 122, and 2.4 before build 375, when Exchange Server is used, allow local users to read cleartext administrator credentials via unspecified vectors.
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 0.33% probability · 26th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-255
- Affected
- emc/networker module for microsoft applications
- Source
- security_alert@emc.com
References
- http://archives.neohapsis.com/archives/bugtraq/2012-10/0068.html
- http://osvdb.org/86157
- http://secunia.com/advisories/50957
- http://www.securityfocus.com/bid/55883
- http://www.securitytracker.com/id?1027647
- http://archives.neohapsis.com/archives/bugtraq/2012-10/0068.html
- http://osvdb.org/86157
- http://secunia.com/advisories/50957
- http://www.securityfocus.com/bid/55883
- http://www.securitytracker.com/id?1027647
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.