CVE-2012-0402: Critical severity rsa envision vulnerability
Published Mar 20, 2012
·Updated
EMC RSA enVision 4.x before 4.1 Patch 4 uses unspecified hardcoded credentials, which makes it easier for remote attackers to obtain access via unknown vectors.
Affected Software
5 affected components
RSA EnVision=4.0-sp1
RSA EnVision=4.0-sp2
RSA EnVision=4.0-sp3
RSA EnVision=4.0-sp4
RSA EnVision=4.1
Event History
Mar 20, 2012
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-0402?
The severity of CVE-2012-0402 is medium, given its potential for unauthorized access due to hardcoded credentials.
2
How do I fix CVE-2012-0402?
To fix CVE-2012-0402, update your RSA enVision to version 4.1 Patch 4 or a later version.
3
What versions of RSA enVision are affected by CVE-2012-0402?
RSA enVision versions 4.0 SP1, 4.0 SP2, 4.0 SP3, 4.0 SP4, and 4.1 before Patch 4 are affected by CVE-2012-0402.
4
Can CVE-2012-0402 be exploited remotely?
Yes, CVE-2012-0402 can be exploited remotely by attackers due to the use of hardcoded credentials.
5
What should I do if I can't immediately update for CVE-2012-0402?
If an immediate update isn't possible, consider implementing network restrictions to limit access to the affected RSA enVision systems.