Vulnerability Description
McAfee Enterprise Mobility Manager (EMM) Agent before 4.8 and Server before 10.1 record all invalid usernames presented in failed login attempts, and place them on a list of accounts that an administrator may wish to unlock, which allows remote attackers to cause a denial of service (excessive list size in the EMM Database) via a long sequence of login attempts with different usernames.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mcafee | Enterprise Mobility Manager | <= 4.7 |
| Mcafee | Enterprise Mobility Manager Agent | <= 10.0 |
Related Weaknesses (CWE)
References
- https://kc.mcafee.com/corporate/index?page=content&id=SB10021Vendor Advisory
- https://kc.mcafee.com/corporate/index?page=content&id=SB10021Vendor Advisory
FAQ
What is CVE-2012-4588?
CVE-2012-4588 is a vulnerability with a CVSS score of 4.3 (MEDIUM). McAfee Enterprise Mobility Manager (EMM) Agent before 4.8 and Server before 10.1 record all invalid usernames presented in failed login attempts, and place them on a list of accounts that an administr...
How severe is CVE-2012-4588?
CVE-2012-4588 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2012-4588?
Check the references section above for vendor advisories and patch information. Affected products include: Mcafee Enterprise Mobility Manager, Mcafee Enterprise Mobility Manager Agent.