← Vulnerability feed

Vulnerability record · CVE-2012-3419 · published 27 August 2012

CVE-2012-3419: Sgi performance co-pilot information exposure vulnerability

Sgi · Performance Co Pilot

Performance Co-Pilot (PCP) before 3.6.5 exports some of the /proc file system, which allows attackers to obtain sensitive information such as proc/pid/maps and command line arguments.

5.0 CVSS 2.0 Medium EPSS 1.8% · top 23.0% CWE-200 · Information exposure
5.0CVSS 2.0 base score
1.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
20References
16 Jun 2026Last modified by NVD

Description

Performance Co-Pilot (PCP) before 3.6.5 exports some of the /proc file system, which allows attackers to obtain sensitive information such as proc/pid/maps and command line arguments.

AV:N/AC:L/Au:N/C:P/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-3419 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.2CVE-2001-0823Sgi performance co-pilot vulnerabilityThe pmpost program in Performance Co-Pilot (PCP) before 2.2.1-3 allows a local user to gain privileges via a symlink attack on the NOTICES file in th…EPSS 0.98%6.7CVE-2023-6917Sgi performance co-pilot toctou race condition vulnerabilityA vulnerability has been identified in the Performance Co-Pilot (PCP) package, stemming from the mixed privilege levels utilized by systemd services …EPSS 0.20%5.0CVE-2012-3418Sgi performance co-pilot vulnerabilitylibpcp in Performance Co-Pilot (PCP) before 3.6.5 allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a …EPSS 5.7%5.0CVE-2012-3420Sgi performance co-pilot vulnerabilityMultiple memory leaks in Performance Co-Pilot (PCP) before 3.6.5 allow remote attackers to cause a denial of service (memory consumption or daemon cr…EPSS 2.4%5.0CVE-2012-3421Sgi performance co-pilot vulnerabilityThe pduread function in pdu.c in libpcp in Performance Co-Pilot (PCP) before 3.6.5 does not properly time out connections, which allows remote attack…EPSS 3.3%2.1CVE-2012-5530Sgi performance co-pilot permissions and access controls vulnerabilityThe (1) pcmd and (2) pmlogger init scripts in Performance Co-Pilot (PCP) before 3.6.10 allow local users to overwrite arbitrary files via a symlink a…EPSS 0.37%5.9CVE-2025-68686FortiOS symbolic link patch bypass exposes sensitive informationFortiOS contains an information exposure flaw (CWE-200) that lets a remote unauthenticated attacker bypass the patch for the symbolic link persistenc…KEVEPSS 30%analysed7.5CVE-2026-20133Cisco Catalyst SD-WAN Manager insufficient file system restrictions expose dataCisco Catalyst SD-WAN Software has insufficient file system restrictions that let an attacker read sensitive files on the underlying operating system…KEVEPSS 32%analysed

Source: NIST National Vulnerability Database (record CVE-2012-3419), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.