Lucene search

K
cveCiscoCVE-2012-4089
HistorySep 24, 2013 - 10:35 a.m.

CVE-2012-4089

2013-09-2410:35:51
CWE-20
cisco
web.nvd.nist.gov
25
cve
2012
4089
cisco
ucs
fabric interconnect
mctools
privilege escalation
bmc
bug id
csctg76239
nvd

CVSS2

6.6

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:S/C:C/I:C/A:C

AI Score

7.4

Confidence

High

EPSS

0

Percentile

5.1%

MCTOOLS in the fabric interconnect in Cisco Unified Computing System (UCS) allows local users to execute arbitrary Baseboard Management Controller (BMC) commands by leveraging (1) local, (2) shell-level, or (3) debug-level privileges at the operating-system layer, aka Bug ID CSCtg76239.

Affected configurations

Nvd
Node
ciscounified_computing_systemMatch-
VendorProductVersionCPE
ciscounified_computing_system-cpe:2.3:h:cisco:unified_computing_system:-:*:*:*:*:*:*:*

CVSS2

6.6

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:S/C:C/I:C/A:C

AI Score

7.4

Confidence

High

EPSS

0

Percentile

5.1%

Related for CVE-2012-4089