Lucene search

K
cve[email protected]CVE-2012-4116
HistoryOct 03, 2022 - 4:15 p.m.

CVE-2012-4116

2022-10-0316:15:34
CWE-200
web.nvd.nist.gov
23
cisco
ucs
security vulnerability
fabric-interconnect
kvm
encryption
remote attack

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

AI Score

6.9

Confidence

Low

EPSS

0.002

Percentile

53.5%

The fabric-interconnect component in Cisco Unified Computing System (UCS) does not encrypt KVM media traffic, which allows remote attackers to obtain sensitive information, and consequently complete the authentication process for a server connection, by sniffing the network, aka Bug ID CSCtr72970.

Affected configurations

NVD
Node
ciscounified_computing_systemMatch-
VendorProductVersionCPE
ciscounified_computing_system-cpe:/h:cisco:unified_computing_system:-:::

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

AI Score

6.9

Confidence

Low

EPSS

0.002

Percentile

53.5%

Related for CVE-2012-4116