VulnerabilityModified
CVE-2012-2681
Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, uses predictable random numbers to generate session keys, which makes it easier for remote attackers to guess the session key.
MEDIUM 5.8EPSS 2.20%
Does this matter?
Lower severity and a low EPSS score (2.20%). Track it; it rarely justifies an emergency change on its own.
Description
Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, uses predictable random numbers to generate session keys, which makes it easier for remote attackers to guess the session key.
- CVSS 2.0
- 5.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
- EPSS
- 2.20% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-310
- Affected
- trevor mckay/cumin · redhat/enterprise mrg
- Source
- secalert@redhat.com
References
- http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=827558Exploit
- http://rhn.redhat.com/errata/RHSA-2012-1278.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2012-1281.htmlVendor Advisory
- http://secunia.com/advisories/50660
- http://www.securityfocus.com/bid/55618
- https://exchange.xforce.ibmcloud.com/vulnerabilities/78771
- http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=827558Exploit
- http://rhn.redhat.com/errata/RHSA-2012-1278.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2012-1281.htmlVendor Advisory
- http://secunia.com/advisories/50660
- http://www.securityfocus.com/bid/55618
- https://exchange.xforce.ibmcloud.com/vulnerabilities/78771
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.