Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2012-5968


The Huawei E585 device does not validate the status of admin sessions, which allows remote attackers to obtain sensitive user information and the session ID, and modify data, by leveraging access to the LAN network.


Published

2012-12-19T11:55:59.750

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 4.8 (MEDIUM)

CVSSv2 Vector

AV:A/AC:L/Au:N/C:P/I:P/A:N

  • Access Vector: ADJACENT_NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

6.5

Impact Score

4.9

Weaknesses
  • Type: Primary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Hardware huawei e585 - Yes
Hardware huawei e585u-82 - Yes

References