4
CVSSv2

CVE-2012-4090

Published: 05/10/2013 Updated: 29/08/2017
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

A vulnerability in Cisco NX-OS Software could allow an authenticated, remote malicious user to view sensitive information. The vulnerability is due to improper sanitization of configuration files that can be viewed by users assigned to the network-operator role. An attacker could exploit this vulnerability by accessing the Cisco NX-OS management interface as a network-operator. A successful exploit could allow the malicious user to view sensitive information in the Cisco NX-OS configuration files. Cisco has confirmed the vulnerability in a security notice and has released software updates. To exploit this vulnerability, an attacker requires authenticated access to the targeted system. Authenticated access may require the malicious user to access trusted, internal networks. These access requirements could limit the likelihood of a successful exploit. Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco nx-os -

cisco nexus_7000 -

cisco nexus_7000_18-slot -

cisco nexus_7000_10-slot -

cisco nexus_7000_9-slot -

Vendor Advisories

A vulnerability in Cisco NX-OS Software could allow an authenticated, remote attacker to view sensitive information The vulnerability is due to improper sanitization of configuration files that can be viewed by users assigned to the network-operator role An attacker could exploit this vulnerability by accessing the Cisco NX-OS management interf ...