CVE-2012-3018
Severity CVSS v4.0:
Pending analysis
Type:
CWE-310
Cryptographic Issues
Publication date:
31/07/2012
Last modified:
11/04/2025
Description
The lockout-recovery feature in the Security Configurator component in ICONICS GENESIS32 9.22 and earlier and BizViz 9.22 and earlier uses an improper encryption algorithm for generation of an authentication code, which allows local users to bypass intended access restrictions and obtain administrative access by predicting a challenge response.
Impact
Base Score 2.0
4.40
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:iconics:genesis32:*:*:*:*:*:*:*:* | 9.22 (including) | |
cpe:2.3:a:iconics:genesis32:8.05:*:*:*:*:*:*:* | ||
cpe:2.3:a:iconics:genesis32:9.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:iconics:genesis32:9.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:iconics:genesis32:9.01:*:*:*:*:*:*:* | ||
cpe:2.3:a:iconics:genesis32:9.2:*:*:*:*:*:*:* | ||
cpe:2.3:a:iconics:genesis32:9.13:*:*:*:*:*:*:* | ||
cpe:2.3:a:iconics:genesis32:9.20:*:*:*:*:*:*:* | ||
cpe:2.3:a:iconics:genesis32:9.21:*:*:*:*:*:*:* | ||
cpe:2.3:a:iconics:bizviz:*:*:*:*:*:*:*:* | 9.22 (including) | |
cpe:2.3:a:iconics:bizviz:8.05:*:*:*:*:*:*:* | ||
cpe:2.3:a:iconics:bizviz:9.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:iconics:bizviz:9.01:*:*:*:*:*:*:* | ||
cpe:2.3:a:iconics:bizviz:9.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:iconics:bizviz:9.2:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page