Lucene search

K
cve[email protected]CVE-2012-4136
HistoryOct 03, 2013 - 11:03 a.m.

CVE-2012-4136

2013-10-0311:03:38
CWE-264
web.nvd.nist.gov
26
cisco
ucs
fabric interconnect
vulnerability
remote attack
nvd
cve-2012-4136

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

6.7

Confidence

Low

EPSS

0.004

Percentile

73.0%

The high-availability service in the Fabric Interconnect component in Cisco Unified Computing System (UCS) does not properly bind the cluster service to the management interface, which allows remote attackers to obtain sensitive information or cause a denial of service (peer-syncing outage) via a TELNET connection, aka Bug ID CSCtz72910.

Affected configurations

NVD
Node
ciscounified_computing_systemMatch-
VendorProductVersionCPE
ciscounified_computing_system-cpe:/h:cisco:unified_computing_system:-:::

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

6.7

Confidence

Low

EPSS

0.004

Percentile

73.0%

Related for CVE-2012-4136