CVE-2012-2994

CoSoSys Endpoint Protector 4 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2012-2994. PoCs published by Christopher Campbell.

AI-analyzed exploit summary This PowerShell script exploits an insecure password generation vulnerability in CoSoSys Endpoint Protector 4. It calculates the predictable root password using the device's serial number, allowing an attacker to gain unauthorized access.

Description

The CoSoSys Endpoint Protector 4 appliance establishes an EPProot password based entirely on the appliance serial number, which makes it easier for remote attackers to obtain access via a brute-force attack.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Christopher Campbell · textremotehardware
https://www.exploit-db.com/exploits/37803

This PowerShell script exploits an insecure password generation vulnerability in CoSoSys Endpoint Protector 4. It calculates the predictable root password using the device's serial number, allowing an attacker to gain unauthorized access.

Classification
Working Poc 100%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: CoSoSys Endpoint Protector 4
No auth needed
Prerequisites: knowledge of the target device's serial number
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/591667
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/50604

Scores

EPSS 0.0627
EPSS Percentile 92.7%

Details

CWE
CWE-264
Status published
Products (1)
cososys/endpoint_protector_appliace_4
Published Sep 18, 2012
Tracked Since Feb 18, 2026