CVE-2024-12012
CVSS 3.1 Score 5.7 of 10 (medium)
Details
Published Feb 13, 2025
CWE ID 598
Summary
CVE-2024-12012 is a newly identified vulnerability affecting the 130.8005 TCP/IP Gateway running firmware version 12h. This issue involves CWE-598, or the use of GET request methods with sensitive query strings, which exposes the SHA-1 hash of passwords and session tokens through URLs. An attacker with access to these values, such as through network traffic inspection or victim browsers, can exploit this vulnerability to leak both the password hash and session tokens, effectively bypassing the authentication mechanism via pass-the-hash attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share