LiveActive security incident?Get immediate response
CVE Record

CVE-2012-0425: LanItems.ycp in save_y2logs in yast2-network before 2.24.4 in SUSE YaST writes cleartext Wi-Fi credentials...

LanItems.ycp in save_y2logs in yast2-network before 2.24.4 in SUSE YaST writes cleartext Wi-Fi credentials to the y2log log file, which allows context-dependent attackers to obtain sensitive information by reading the (1) WIRELESS_WPA_PASSWORD or (2) WIRELESS_CLIENT_KEY_PASSWORD field.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

SUSE YaST yast2-network before 2.24.4 could write Wi-Fi passwords or client key passwords into the y2log file. The business risk is credential exposure if someone can read local logs, support bundles, backups, or log aggregation stores containing those files.

Executive priority

Treat as targeted legacy hygiene. It is not a remote code execution issue, but exposed Wi-Fi credentials can enable unauthorized network access if affected logs escaped normal administrative control.

Technical view

LanItems.ycp in save_y2logs logged WIRELESS_WPA_PASSWORD and WIRELESS_CLIENT_KEY_PASSWORD in cleartext. The source bundle identifies yast2-network before 2.24.4 in SUSE YaST. No CVSS, CWE, or normalized affected CPE data is provided.

Likely exposure

Exposure is most likely on legacy SUSE systems using YaST network configuration for Wi-Fi, especially where y2log files were retained, collected centrally, shared with support, or readable by non-administrative users.

Exploitation context

No active exploitation is supported by the provided sources, and the CVE is not listed as KEV. Abuse appears context-dependent: an attacker must obtain access to logs containing the cleartext fields.

Researcher notes

Evidence is limited to the CVE description and vendor reference URLs. The bundle lacks CVSS, CWE, exploit details, and normalized affected product data, so validation should focus on version inventory and historical log exposure.

Mitigation direction

  • Upgrade yast2-network to 2.24.4 or later where available from SUSE guidance.
  • Review and sanitize retained y2log files, support bundles, and backups.
  • Rotate Wi-Fi credentials found in exposed logs.
  • Restrict access to YaST logs and centralized log stores.
  • Check vendor advisories for distribution-specific package names and fixed versions.

Validation and detection

  • Inventory SUSE systems running YaST yast2-network before 2.24.4.
  • Review y2log locations for the named password fields without disclosing secret values.
  • Confirm retained support bundles and backups do not contain exposed credentials.
  • Verify upgraded systems no longer log these cleartext fields.
  • Check log access controls for least-privilege permissions.
Prepared
Confidence
medium
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2012-0425 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
3Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.