5.8
CVSSv2

CVE-2012-4073

Published: 20/09/2013 Updated: 09/09/2016
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

The KVM subsystem in the client in Cisco Unified Computing System (UCS) does not verify X.509 certificates from SSL servers, which allows man-in-the-middle malicious users to spoof servers, and read or modify KVM data, via a crafted certificate, aka Bug ID CSCte90332.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco unified computing system -

Vendor Advisories

A vulnerability in Cisco Unified Computing System software KVM client could allow an unauthenticated, remote attacker to perform a man-in-the-middle attack The vulnerability is due to improper certificate validation by the KVM client An attacker could exploit this vulnerability by intercepting a KVM connection A successful exploit could allow t ...