CVE-2012-3014

high
Published 2012-09-04 · Modified 2026-04-29
CVSS v3
CVSS v2
7.7
VIR risk
7.7

Description

The Management Software application in GarrettCom Magnum MNS-6K before 4.4.0, and 14.x before 14.4.0, has a hardcoded password for an administrative account, which allows local users to gain privileges via unspecified vectors.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: ics-cert@hq.dhs.gov — http://www.garrettcom.com/techsupport/6k_dl/6k440_rn.pdf

Application impact

VendorProductVersionsFixed
garrettcommagnum_managed_networks_software-6k{"endIncluding":"4.3.1"}
garrettcommagnum_managed_networks_software-6k4.2
garrettcommagnum_managed_networks_software-6k4.2.1
garrettcommagnum_managed_networks_software-6k4.3.0
garrettcommagnum_managed_networks_software-6k_secure14.2
garrettcommagnum_managed_networks_software-6k_secure14.2.1
garrettcommagnum_managed_networks_software-6k_secure14.3.0
garrettcommagnum_managed_networks_software-6k_secure14.3.1

References

CWEs

CWE-255

Verify integrity in audit chain (admin only). AS-IS.