Security readout for executives and security teams
Plain-English summary
SUSE YaST yast2-network before 2.24.4 could write Wi-Fi passwords or client key passwords into the y2log file. The business risk is credential exposure if someone can read local logs, support bundles, backups, or log aggregation stores containing those files.
Executive priority
Treat as targeted legacy hygiene. It is not a remote code execution issue, but exposed Wi-Fi credentials can enable unauthorized network access if affected logs escaped normal administrative control.
Technical view
LanItems.ycp in save_y2logs logged WIRELESS_WPA_PASSWORD and WIRELESS_CLIENT_KEY_PASSWORD in cleartext. The source bundle identifies yast2-network before 2.24.4 in SUSE YaST. No CVSS, CWE, or normalized affected CPE data is provided.
Likely exposure
Exposure is most likely on legacy SUSE systems using YaST network configuration for Wi-Fi, especially where y2log files were retained, collected centrally, shared with support, or readable by non-administrative users.
Exploitation context
No active exploitation is supported by the provided sources, and the CVE is not listed as KEV. Abuse appears context-dependent: an attacker must obtain access to logs containing the cleartext fields.
Researcher notes
Evidence is limited to the CVE description and vendor reference URLs. The bundle lacks CVSS, CWE, exploit details, and normalized affected product data, so validation should focus on version inventory and historical log exposure.
Mitigation direction
- Upgrade yast2-network to 2.24.4 or later where available from SUSE guidance.
- Review and sanitize retained y2log files, support bundles, and backups.
- Rotate Wi-Fi credentials found in exposed logs.
- Restrict access to YaST logs and centralized log stores.
- Check vendor advisories for distribution-specific package names and fixed versions.
Validation and detection
- Inventory SUSE systems running YaST yast2-network before 2.24.4.
- Review y2log locations for the named password fields without disclosing secret values.
- Confirm retained support bundles and backups do not contain exposed credentials.
- Verify upgraded systems no longer log these cleartext fields.
- Check log access controls for least-privilege permissions.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2012-0425 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://support.novell.com/security/cve/CVE-2012-0425.htmlCVE reference · x_refsource_CONFIRM
- https://bugzilla.novell.com/show_bug.cgi?id=752464CVE reference · x_refsource_CONFIRM
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
