CVE-2012-1806

Koyo ECOM Ethernet Module - Improper Authentication via Short Password Length

Title source: llm
STIX 2.1

Description

The ECOM Ethernet module in Koyo H0-ECOM, H0-ECOM100, H2-ECOM, H2-ECOM-F, H2-ECOM100, H4-ECOM, H4-ECOM-F, and H4-ECOM100 supports a maximum password length of 8 bytes, which makes it easier for remote attackers to obtain access via a brute-force attack.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/74876
US Government Resource x_refsource_misc
http://www.us-cert.gov/control_systems/pdf/ICSA-12-102-02.pdf

Scores

EPSS 0.0207
EPSS Percentile 79.0%

Details

CWE
CWE-287
Status published
Products (8)
koyo/h0-ecom
koyo/h0-ecom100
koyo/h2-ecom
koyo/h2-ecom-f
koyo/h2-ecom100
koyo/h4-ecom
koyo/h4-ecom-f
koyo/h4-ecom100
Published Apr 13, 2012
Tracked Since Feb 18, 2026