CVE-2012-0425
high
CVSS v3
—
CVSS v2
7.8
VIR risk
7.8
Description
LanItems.ycp in save_y2logs in yast2-network before 2.24.4 in SUSE YaST writes cleartext Wi-Fi credentials to the y2log log file, which allows context-dependent attackers to obtain sensitive information by reading the (1) WIRELESS_WPA_PASSWORD or (2) WIRELESS_CLIENT_KEY_PASSWORD field.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cve@mitre.org — https://support.novell.com/security/cve/CVE-2012-0425.html
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| suse | 12.1 | affected | |
References
CWEs
CWE-200
Verify integrity in audit chain (admin only). AS-IS.