Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerability · NVD

CVE-2012-6140

CVE-2012-6140, Severity pending severity (CVSS —): 2 tracked apps concerned, all fixed or indeterminable on their current version.

Severity (CVSS)
-
Exploitation
0.2 %

EPSS, predicted over 30 days

Tracked apps
2
Still exposed
0

pam_google_authenticator.c in the PAM module in Google Authenticator before 1.0 requires user-readable permissions for the secret file, which allows local users to bypass intended access restrictions and discover a shared secret via standard filesystem operations, a different vulnerability than CVE-2013-0258.

EPSS 0.23% exploit very unlikely percentile 12.2%

Tracked apps referencing this CVE

For each app: the affected range, the fixing version, and where the tracked app stands today.

  • Google Authenticator iOS com.google.OTP
    Affected ≤0.91 Fixed in > 0.91 Latest tracked - undetermined
  • Google Authenticator Android com.google.android.apps.authenticator2
    Affected ≤0.91 Fixed in > 0.91 Latest tracked 7.2 patched
Vulnerable CPE configurations (6)
Vendor Product Versions
google authenticator
All platforms (wildcard)
≤0.91
google authenticator
All platforms (wildcard)
≤0.91
google authenticator
All platforms (wildcard)
-
google authenticator
All platforms (wildcard)
-
google authenticator
All platforms (wildcard)
-
google authenticator
All platforms (wildcard)
-
View on NVD ↗

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM