Lucene search

K
ciscoCiscoCISCO-SA-20130924-CVE-2012-4094
HistorySep 24, 2013 - 7:45 p.m.

Cisco Unified Computing System Fabric Interconnect Denial of Service Vulnerability

2013-09-2419:45:27
tools.cisco.com
9

CVSS2

5.4

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:H/Au:N/C:N/I:N/A:C

EPSS

0.004

Percentile

72.1%

A vulnerability in Smart Call Home functionality in the fabric interconnect (FI) of Cisco Unified Computing System could allow an
unauthenticated, remote attacker to create a denial of service (DoS) condition.

The
vulnerability is due to a buffer overflow in the Smart Call Home
function. An attacker could exploit this vulnerability by intercepting
and spoofing certain control messages that cause Smart Call Home to send a
report.

Cisco has confirmed the vulnerability in a security notice and has released software updates.

To exploit this vulnerability, an attacker may require access to trusted, internal networks to send crafted requests to the affected software. This access requirement could limit the likelihood of a successful exploit.

Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.

Affected configurations

Vulners
Node
ciscounified_computing_systemMatchany
OR
ciscounified_computing_systemMatchany

CVSS2

5.4

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:H/Au:N/C:N/I:N/A:C

EPSS

0.004

Percentile

72.1%

Related for CISCO-SA-20130924-CVE-2012-4094