CVE-2012-4578
low
CVSS v3
—
CVSS v2
2.1
VIR risk
2.1
Description
The geli encryption provider 7 before r239184 on FreeBSD 10 uses a weak Master Key, which makes it easier for local users to defeat a cryptographic protection mechanism via a brute-force attack.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cve@mitre.org — http://lists.freebsd.org/pipermail/freebsd-security/2012-August/006541.html
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| freebsd | 10.0 | not-affected | |
References
CWEs
CWE-310
Verify integrity in audit chain (admin only). AS-IS.