CVE-2012-3268

Severity CVSS v4.0:
Pending analysis
Type:
CWE-522 Insufficiently Protected Credentials
Publication date:
01/02/2013
Last modified:
11/04/2025

Description

Certain HP Access Controller, Fabric Module, Firewall, Router, Switch, and UTM Appliance products; certain HP 3Com Access Controller, Router, and Switch products; certain HP H3C Access Controller, Firewall, Router, Switch, and Switch and Route Processing Unit products; and certain Huawei Firewall/Gateway, Router, Switch, and Wireless products do not properly implement access control as defined in h3c-user.mib 2.0 and hh3c-user.mib 2.0, which allows remote authenticated users to discover credentials in UserInfoEntry values via an SNMP request with the read-only community.

Vulnerable products and versions

CPE From Up to
cpe:2.3:h:hp:0150a129:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:0150a12a:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:0150a12b:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:0150a12c:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:0231a0av:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:0231a65t:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:0231a761:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:0231a832:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:0231a86p:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:0231a88a:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:0231a88l:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:0235a08f:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:0235a08h:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:0235a08k:-:*:*:*:*:*:*:*
cpe:2.3:h:hp:0235a08m:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools