Vulnerability Name: | CVE-2012-2681 (CCN-78771) | ||||||||
Assigned: | 2012-09-19 | ||||||||
Published: | 2012-09-19 | ||||||||
Updated: | 2021-07-15 | ||||||||
Summary: | Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, uses predictable random numbers to generate session keys, which makes it easier for remote attackers to guess the session key. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 5.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N) 4.3 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-310 | ||||||||
Vulnerability Consequences: | Other | ||||||||
References: | Source: MISC Type: Exploit http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=827558 Source: MITRE Type: CNA CVE-2012-2681 Source: CCN Type: RHSA-2012-1278 Moderate: Red Hat Enterprise MRG Grid 2.2 security update Source: REDHAT Type: Vendor Advisory RHSA-2012:1278 Source: CCN Type: RHSA-2012-1281 Moderate: Red Hat Enterprise MRG Grid 2.2 security update Source: REDHAT Type: Vendor Advisory RHSA-2012:1281 Source: CCN Type: SA50660 Cumin Multiple Vulnerabilities Source: SECUNIA Type: UNKNOWN 50660 Source: CCN Type: Cumin SVN Repository Cumin Source: BID Type: UNKNOWN 55618 Source: CCN Type: BID-55618 Cumin Multiple Remote Vulnerabilities Source: CCN Type: Red Hat Bugzilla Bug 827558 CVE-2012-2681 cumin: weak session keys Source: XF Type: UNKNOWN cumin-redhat-weak-security(78771) Source: XF Type: UNKNOWN cumin-redhat-weak-security(78771) Source: CCN Type: Cumin Web page Cumin | ||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
BACK |