MEDIUM · 4.3

CVE-2012-4588

McAfee Enterprise Mobility Manager (EMM) Agent before 4.8 and Server before 10.1 record all invalid usernames presented in failed login attempts, and place them on a list of accounts that an administr...

Vulnerability Description

McAfee Enterprise Mobility Manager (EMM) Agent before 4.8 and Server before 10.1 record all invalid usernames presented in failed login attempts, and place them on a list of accounts that an administrator may wish to unlock, which allows remote attackers to cause a denial of service (excessive list size in the EMM Database) via a long sequence of login attempts with different usernames.

CVSS Score

4.3

MEDIUM

AV:N/AC:M/Au:N/C:N/I:N/A:P
Confidentiality
NONE
Integrity
NONE
Availability
PARTIAL

Affected Products

VendorProductVersions
McafeeEnterprise Mobility Manager<= 4.7
McafeeEnterprise Mobility Manager Agent<= 10.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2012-4588?

CVE-2012-4588 is a vulnerability with a CVSS score of 4.3 (MEDIUM). McAfee Enterprise Mobility Manager (EMM) Agent before 4.8 and Server before 10.1 record all invalid usernames presented in failed login attempts, and place them on a list of accounts that an administr...

How severe is CVE-2012-4588?

CVE-2012-4588 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2012-4588?

Check the references section above for vendor advisories and patch information. Affected products include: Mcafee Enterprise Mobility Manager, Mcafee Enterprise Mobility Manager Agent.