5.8
CVSSv2

CVE-2012-4074

Published: 20/09/2013 Updated: 23/09/2016
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

The Board Management Controller (BMC) in the Serial over LAN (SoL) subsystem in Cisco Unified Computing System (UCS) relies on a hardcoded private key, which allows man-in-the-middle malicious users to obtain sensitive information or modify the data stream by leveraging knowledge of this key, aka Bug ID CSCte90338.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco unified computing system -

Vendor Advisories

A vulnerability in the Cisco Unified Computing System Serial over LAN (SoL) implementation could allow an unauthenticated, remote attacker to perform a man-in-the-middle (MITM) attack The vulnerability occurs because the Board Management Controller (BMC) uses a hard-coded private key An attacker could exploit this vulnerability by intercepting ...