Unrated severityNVD Advisory· Published Aug 22, 2012· Updated Apr 29, 2026
CVE-2012-4587
CVE-2012-4587
Description
McAfee Enterprise Mobility Manager (EMM) Agent before 4.8 and Server before 10.1, when one-time provisioning (OTP) mode is enabled, have an improper dependency on DNS SRV records, which makes it easier for remote attackers to discover user passwords by spoofing the EMM server, as demonstrated by a password entered on an iOS device.
Affected products
2- cpe:2.3:a:mcafee:enterprise_mobility_manager:*:*:*:*:*:*:*:*Range: <=4.7
- cpe:2.3:a:mcafee:enterprise_mobility_manager_agent:*:*:*:*:*:*:*:*Range: <=10.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- kc.mcafee.com/corporate/indexnvdVendor Advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/78130nvd
News mentions
0No linked articles in our index yet.