Lucene search

K
ciscoCiscoCISCO-SA-20130927-CVS-2012-4136
HistorySep 27, 2013 - 2:07 a.m.

Cisco Unified Computing System Fabric Interconnect Remote Access Vulnerability

2013-09-2702:07:48
tools.cisco.com
17

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.004

Percentile

73.0%

A vulnerability in the high availability service of Cisco
Unified Computing System Fabric Interconnect could allow an
unauthenticated, remote attacker to gain access to sensitive information
and prevent the cluster service from syncing with its peers.

The
vulnerability is due to improper binding of the cluster service to the
management interface. An attacker could exploit this vulnerability by
establishing a Telnet connection to the cluster service from a remote
location. A successful exploit could allow the attacker to gain access
to sensitive information and modify a field that results in the
cluster service unable to sync with its peers.

Cisco has confirmed the vulnerability in a security notice and released software updates.

To exploit this vulnerability, an attacker must be able to establish a Telnet connection to the cluster service from a remote location. It is likely that this cluster service would reside on a device in an internal trusted network to which an attacker would need access. In addition, the attacker would need to know the name or IP address associated with the targeted device in an attempt to establish a connection.

It is recommended to use SSH instead of Telnet, as SSH is the more secured method of establishing remote connections.

Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.

Affected configurations

Vulners
Node
ciscounified_computing_systemMatchany
OR
ciscounified_computing_systemMatchany

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.004

Percentile

73.0%

Related for CISCO-SA-20130927-CVS-2012-4136