Vulnerability record · CVE-2012-0432 · published 25 December 2012
CVE-2012-0432: NetIQ eDirectory NCP stack buffer overflow
Microfocus · Edirectory
NetIQ eDirectory 8.8.7.x before 8.8.7.2 contains a stack-based buffer overflow in its Novell NCP implementation. The flaw is remotely reachable over the network with no authentication, and the record does not specify the exact vectors or the resulting impact beyond 'unspecified'.
Description
Stack-based buffer overflow in the Novell NCP implementation in NetIQ eDirectory 8.8.7.x before 8.8.7.2 allows remote attackers to have an unspecified impact via unknown vectors.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 score of 10 with a network, unauthenticated vector and a 99th-percentile EPSS score make this a top remediation priority despite thin exploit detail.
What it is
NetIQ eDirectory 8.8.7.x before 8.8.7.2 contains a stack-based buffer overflow in its Novell NCP implementation. The flaw is remotely reachable over the network with no authentication, and the record does not specify the exact vectors or the resulting impact beyond 'unspecified'.
Impact
An unauthenticated remote attacker could corrupt stack memory in the eDirectory NCP service, potentially leading to code execution or a denial of service. The record does not state the precise impact, so the full consequence is unconfirmed.
Attack surface
Reached over the network via the NCP protocol implementation in eDirectory, per the AV:N/AC:L/Au:N vector. No authentication or user interaction is required.
Exploitation
Not listed in CISA KEV and no reference is tagged as exploit code, but EPSS is 0.587 (99th percentile), indicating high predicted exploitation activity despite the absence of confirmed public exploits in this record.
What to do
- Upgrade eDirectory to 8.8.7.2 or later, which is the fixed version named in the description.
- Restrict network access to NCP ports to trusted hosts and segments until patching is complete.
- Monitor Novell support KB 3426981 and Bugzilla 785272 for vendor guidance and any updated fixed versions.
- Segment or isolate eDirectory servers that must expose NCP to untrusted networks.
Detection
- Monitor eDirectory NCP service processes for crashes or abnormal termination that could indicate malformed packet handling.
- Inspect network traffic to NCP ports for oversized or malformed requests targeting the eDirectory service.
- Correlate host and network logs for repeated unauthenticated NCP connection attempts from unexpected sources.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-0432 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-0432), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.