U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-12012

Change History

New CVE Received from Nozomi Networks Inc. 2/13/2025 11:15:43 AM

Action Type Old Value New Value
Added Description

								
							
							
						
A CWE-598 “Use of GET Request Method with Sensitive Query Strings” was discovered affecting the 130.8005 TCP/IP Gateway running firmware version 12h. Both the SHA-1 hash of the password as well as the session tokens are included as part of the URL and therefore exposed to information leakage scenarios. An attacker capable of accessing such values (e.g., victim browser, network traffic inspection) can exploit this vulnerability to leak both the password hash as well as session tokens and bypass the authentication mechanism using a pass-the-hash attack.
Added CVSS V3.1

								
							
							
						
AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Added CWE

								
							
							
						
CWE-598
Added Reference

								
							
							
						
https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-12012