First published: Tue Mar 20 2012(Updated: )
EMC RSA enVision 4.x before 4.1 Patch 4 uses unspecified hardcoded credentials, which makes it easier for remote attackers to obtain access via unknown vectors.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
RSA enVision | =4.0-sp1 | |
RSA enVision | =4.0-sp2 | |
RSA enVision | =4.0-sp3 | |
RSA enVision | =4.0-sp4 | |
RSA enVision | =4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2012-0402 is medium, given its potential for unauthorized access due to hardcoded credentials.
To fix CVE-2012-0402, update your RSA enVision to version 4.1 Patch 4 or a later version.
RSA enVision versions 4.0 SP1, 4.0 SP2, 4.0 SP3, 4.0 SP4, and 4.1 before Patch 4 are affected by CVE-2012-0402.
Yes, CVE-2012-0402 can be exploited remotely by attackers due to the use of hardcoded credentials.
If an immediate update isn't possible, consider implementing network restrictions to limit access to the affected RSA enVision systems.