Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2012-3359

16
FAUCET Score

CVE-2012-3359 describes a vulnerability in Luci within Red Hat Conga and Red Hat Enterprise Linux where user credentials (username and password) are stored as a Base64 encoded string in the __ac session cookie. This allows an attacker with local access to the system to potentially gain privileges by accessing this cookie. The vulnerability has a CVSS score of 3.7, indicating low severity, with an attack vector requiring local access and high attack complexity, leading to partial confidentiality, integrity, and availability impacts. There is no known exploit intelligence, such as Metasploit modules or ExploitDB entries, and the vulnerability has received no community discussion or media coverage, suggesting a low likelihood of active exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
All Versions ImpactedCPE matchmatch criteria
cpe:2.3:a:redhat:conga:*:*:*:*:*:*:*:*
5CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux:5:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

3.7LOW

AV:L/AC:H/Au:N/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
LOCAL
Access Complexity
HIGH
Authentication
NONE
Exploitability Score
1.9
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
0.34%
Probability of exploitation in next 30 days
EPSS Percentile
26.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0034 is in the 44th percentile among its peer group of 747 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: conga-0:0.12.2-64.el5
View patch
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: conga

Vendor Advisories (1)

redhatCVE-2012-3359Low

conga: insecure handling of luci web interface sessions

Jan 7, 2013

References

rhn.redhat.com / errata/RHSA-2013-0128.html
Vendor Advisory
bugzilla.redhat.com / show_bug.cgi