4.3
CVSSv2

CVE-2012-4072

Published: 20/09/2013 Updated: 23/09/2016
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

The KVM subsystem in Cisco Unified Computing System (UCS) relies on a hardcoded X.509 certificate, which allows man-in-the-middle malicious users to spoof SSL servers, and read keyboard and mouse events, by leveraging knowledge of this certificate's private key, aka Bug ID CSCte90327.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco unified computing system -

Vendor Advisories

A vulnerability in Cisco Unified Computing System software KVM could allow an unauthenticated, remote attacker to intercept a KVM connection to spoof a host or decrypt keyboard and mouse events on an encrypted channel The vulnerability is due to a hard coded SSL certificate An attacker could exploit this vulnerability by intercepting a KVM conne ...