5
CVSSv2

CVE-2012-5508

Published: 03/11/2014 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The error pages in Plone prior to 4.2.3 and 4.3 before beta 1 allow remote malicious users to obtain random numbers and derive the PRNG state for password resets via unspecified vectors. NOTE: this identifier was SPLIT per ADT2 due to different vulnerability types. CVE-2012-6661 was assigned for the PRNG reseeding issue in Zope.

Vulnerable Product Search on Vulmon Subscribe to Product

plone plone 3.3

plone plone 1.0

plone plone 4.0.5

plone plone 3.0.1

plone plone 1.0.3

plone plone 3.0

plone plone 3.2.3

plone plone 3.1.4

plone plone 3.1.5.1

plone plone 2.1.4

plone plone 4.0.2

plone plone 3.3.5

plone plone 3.0.6

plone plone 2.5.4

plone plone 3.2

plone plone 3.1.1

plone plone 4.3

plone plone 2.1.1

plone plone 3.3.4

plone plone 2.0.3

plone plone 1.0.4

plone plone 3.3.2

plone plone 2.0

plone plone 4.1.6

plone plone 4.0.4

plone plone 3.1.7

plone plone 2.5.1

plone plone 4.1

plone plone 2.5.3

plone plone 3.2.2

plone plone 2.0.4

plone plone 2.1.2

plone plone 1.0.1

plone plone 3.0.3

plone plone 3.3.1

plone plone 3.0.4

plone plone 4.1.4

plone plone 2.0.1

plone plone 2.0.2

plone plone 3.1.2

plone plone 3.2.1

plone plone 4.0

plone plone 1.0.2

plone plone 2.0.5

plone plone 4.1.5

plone plone 3.0.5

plone plone 4.0.6.1

plone plone 2.5

plone plone 1.0.6

plone plone 2.5.2

plone plone 4.0.1

plone plone 3.0.2

plone plone 2.1

plone plone 3.1

plone plone

plone plone 3.3.3

plone plone 2.1.3

plone plone 3.1.6

plone plone 3.1.3

plone plone 4.0.3

plone plone 1.0.5

plone plone 2.5.5

plone plone 4.2

plone plone 4.2.1