CVE-2012-1348
published 2012-08-06CVE-2012-1348: Cisco Wide Area Application Services (WAAS) appliances with software 4.4, 5.0, and 5.1 include a one-way hash of a password within output text, which might…
PriorityP420medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.19%
64.2th percentile
Cisco Wide Area Application Services (WAAS) appliances with software 4.4, 5.0, and 5.1 include a one-way hash of a password within output text, which might allow remote attackers to obtain sensitive information via a brute-force attack on the hash string, aka Bug ID CSCty17279.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | wide_area_application_services | — | — |
| cisco | wide_area_application_services | — | — |
| cisco | wide_area_application_services | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4r8w-vcjg-cxx6: Cisco Wide Area Application Services (WAAS) appliances with software 4
ghsa_unreviewed·2022-05-17
CVE-2012-1348 [MEDIUM] CWE-200 GHSA-4r8w-vcjg-cxx6: Cisco Wide Area Application Services (WAAS) appliances with software 4
Cisco Wide Area Application Services (WAAS) appliances with software 4.4, 5.0, and 5.1 include a one-way hash of a password within output text, which might allow remote attackers to obtain sensitive information via a brute-force attack on the hash string, aka Bug ID CSCty17279.
Cisco
Cisco Wide Area Application Services Appliances One-Way Hash Information Disclosure Vulnerability
vendor_cisco·2012-08-10·CVSS 5.0
CVE-2012-1348 [MEDIUM] CWE-310 Cisco Wide Area Application Services Appliances One-Way Hash Information Disclosure Vulnerability
Cisco Wide Area Application Services Appliances One-Way Hash Information Disclosure Vulnerability
Cisco Wide Area Application Services Appliances software contains a vulnerability that could allow an unauthenticated, remote attacker to gain access to sensitive information.
The vulnerability is due to a design error that allows user passwords to be displayed within output text as a one-way hash on a vulnerable system. An unauthenticated, remote attacker could exploit this vulnerability by conducting a brute-force attack on the one-way hash of a password. If the brute-force attack is successful, the attacker could access sensitive information to gain unauthorized access to the targeted system, which could be used to launch additional attacks.
Cisco has confirmed this vulnerability and rel
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2012-08-06
Published