7.1
CVSSv2

CVE-2012-3063

Published: 20/06/2012 Updated: 22/03/2013
CVSS v2 Base Score: 7.1 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 632
Vector: AV:N/AC:H/Au:S/C:C/I:C/A:C

Vulnerability Summary

Cisco Application Control Engine (ACE) before A4(2.3) and A5 before A5(1.1), when multicontext mode is enabled, does not properly share a management IP address among multiple contexts, which allows remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances, and read or modify configuration settings, via a login attempt to a context, aka Bug ID CSCts30631, a different vulnerability than CVE-2012-3058.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco application control engine software a5\\(1.0\\)

cisco application control engine software a3\\(1.0\\)

cisco application control engine software a1\\(7\\)

cisco application control engine software a1\\(8\\)

cisco application control engine software a1\\(8a\\)

cisco application control engine software a1\\(7b\\)

cisco application control engine software a3\\(2.4\\)

cisco application control engine software a3\\(2.2\\)

cisco application control engine software a3\\(2.3\\)

cisco application control engine software a3\\(2.1\\)

cisco application control engine software a4\\(1.1\\)

cisco application control engine software a4\\(1.0\\)

cisco application control engine software

cisco application control engine software a4\\(2.2\\)

cisco application control engine software a1\\(7a\\)

cisco application control engine software a3\\(2.7\\)

cisco application control engine software a3\\(2.5\\)

cisco application control engine software a4\\(2.1\\)

cisco application control engine software a3\\(2.6\\)