Lucene search

K
ciscoCiscoCISCO-SA-20130918-CVE-2012-4072
HistorySep 18, 2013 - 4:20 p.m.

Cisco Unified Computing System Software KVM Encryption Vulnerability

2013-09-1816:20:46
tools.cisco.com
14

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

EPSS

0.001

Percentile

38.3%

A vulnerability in Cisco Unified Computing System software KVM could allow an unauthenticated, remote attacker to intercept a KVM connection to spoof a host or decrypt keyboard and mouse events on an encrypted channel.

The vulnerability is due to a hard coded SSL certificate. An attacker could exploit this vulnerability by intercepting a KVM connection. An exploit could allow the attacker to spoof a host or decrypt keyboard and mouse events.

Cisco has confirmed the vulnerability in a security notice and released software updates.

To exploit this vulnerability, an attacker must be in the position to intercept a KVM connection on a targeted device which may reside on trusted, internal networks. As a result, the location of the targeted device may reduce the likelihood of a successful exploit.

Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.

Affected configurations

Vulners
Node
ciscounified_computing_systemMatchany
OR
ciscounified_computing_systemMatchany
VendorProductVersionCPE
ciscounified_computing_systemanycpe:2.3:h:cisco:unified_computing_system:any:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

EPSS

0.001

Percentile

38.3%

Related for CISCO-SA-20130918-CVE-2012-4072