CVE-2012-1838 describes an authentication bypass vulnerability in the web management interface of the LG-Nortel ELO GS24M switch. An attacker can directly request configuration web pages, gaining unauthorized access to cleartext credentials and sensitive configuration data. This vulnerability has a CVSS score of 5.0, indicating a medium severity, as it requires no authentication and has a low attack complexity. While there is no known active exploitation or public exploit code, the vulnerability has received some community attention, with one mention on Reddit.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:h:lg-nortel:elo_gs24m_switch:-:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.