Vulnerability Name:

CVE-2012-2395 (CCN-75902)

Assigned:2012-05-29
Published:2012-05-29
Updated:2023-02-13
Summary:
CVSS v3 Severity:7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
5.5 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Consequences:Gain Access
References:Source: CCN
Type: Cobbler Web site
Cobbler

Source: MITRE
Type: CNA
CVE-2012-2395

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: CCN
Type: RHSA-2012-1060
Moderate: cobbler security update

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: CCN
Type: OSVDB ID: 82458
Cobbler xmlrpc API power_system Method Remote Shell Command Execution

Source: CCN
Type: BID-53666
Cobbler Remote Command Injection Vulnerability

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: XF
Type: UNKNOWN
cobbler-xmlrpcapi-command-exec(75902)

Source: secalert@redhat.com
Type: Exploit, Patch
secalert@redhat.com

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Oval Definitions
Definition IDClassTitleLast Modified
oval:org.opensuse.security:def:20122395
V
CVE-2012-2395
2022-06-30
oval:org.opensuse.security:def:112086
P
cobbler-2.6.6-4.2 on GA media (Moderate)
2022-01-17
oval:org.opensuse.security:def:32204
P
Security update for the Linux Kernel (Live Patch 36 for SLE 12 SP3) (Important)
2021-10-18
oval:org.opensuse.security:def:105628
P
cobbler-2.6.6-4.2 on GA media (Moderate)
2021-10-01
oval:org.opensuse.security:def:32111
P
Security update for MozillaFirefox (Important)
2021-06-08
oval:org.opensuse.security:def:32261
P
Security update for krb5-appl (Important)
2021-02-19
oval:org.opensuse.security:def:96468
P
Security update for cobbler (Moderate)
2021-01-14
oval:org.opensuse.security:def:103158
P
Security update for cobbler (Moderate)
2021-01-14
oval:org.opensuse.security:def:109815
P
Security update for cobbler (Moderate)
2021-01-14
oval:org.opensuse.security:def:11200
P
Security update for cobbler (Moderate)
2021-01-14
oval:org.opensuse.security:def:111282
P
Security update for cobbler (Moderate)
2021-01-11
oval:org.opensuse.security:def:29300
P
Security update for python-cryptography (Moderate)
2020-12-04
oval:org.opensuse.security:def:32348
P
Security update for sqlite3 (Important)
2020-12-01
oval:org.opensuse.security:def:28084
P
Security update for gd (Moderate)
2020-12-01
oval:org.opensuse.security:def:31893
P
Security update for expat (Moderate)
2020-12-01
oval:org.opensuse.security:def:28662
P
Security update for finch
2020-12-01
oval:org.opensuse.security:def:32560
P
libopenssl0_9_8 on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:28225
P
Security update for libsndfile (Moderate)
2020-12-01
oval:org.opensuse.security:def:31905
P
Security update for freeradius-server (Moderate)
2020-12-01
oval:org.opensuse.security:def:29336
P
Security update for cobbler
2020-12-01
oval:org.opensuse.security:def:32648
P
dbus-1 on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:28461
P
Security update for xorg-x11-libX11 (Moderate)
2020-12-01
oval:org.opensuse.security:def:27881
P
Security update for rubygem-activesupport-3_2 (Moderate)
2020-12-01
oval:org.opensuse.security:def:32714
P
libgtop on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:28563
P
Security update for inkscape
2020-12-01
oval:org.opensuse.security:def:27956
P
Security update for ImageMagick (Moderate)
2020-12-01
oval:org.opensuse.security:def:33391
P
Security update for cobbler
2020-12-01
oval:org.opensuse.security:def:28618
P
Security update for xorg-x11-libXp
2020-12-01
oval:org.opensuse.security:def:32504
P
emacs on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:28168
P
Security update for the Linux Kernel (Important)
2020-12-01
oval:org.opensuse.security:def:31894
P
Security update for fetchmail (Moderate)
2020-12-01
oval:org.opensuse.security:def:32609
P
tar on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:28309
P
Security update for openslp (Important)
2020-12-01
oval:org.opensuse.security:def:31979
P
Security update for java-1_7_1-ibm (Important)
2020-12-01
oval:org.opensuse.security:def:27880
P
Security update for rubygem-activesupport-3_2
2020-12-01
oval:org.opensuse.security:def:32670
P
gd on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:28514
P
Security update for openssl1 (Important)
2020-12-01
oval:org.opensuse.security:def:27892
P
Security update for samba (Important)
2020-12-01
oval:org.opensuse.security:def:33352
P
Security update for openssl (Important)
2020-12-01
oval:org.opensuse.security:def:28602
P
Security update for telepathy-idle
2020-12-01
oval:com.ubuntu.xenial:def:201223950000000
V
CVE-2012-2395 on Ubuntu 16.04 LTS (xenial) - medium.
2012-06-16
oval:com.ubuntu.artful:def:20122395000
V
CVE-2012-2395 on Ubuntu 17.10 (artful) - medium.
2012-06-15
oval:com.ubuntu.precise:def:20122395000
V
CVE-2012-2395 on Ubuntu 12.04 LTS (precise) - medium.
2012-06-15
oval:com.ubuntu.trusty:def:20122395000
V
CVE-2012-2395 on Ubuntu 14.04 LTS (trusty) - medium.
2012-06-15
oval:com.ubuntu.xenial:def:20122395000
V
CVE-2012-2395 on Ubuntu 16.04 LTS (xenial) - medium.
2012-06-15
BACK