5.8
CVSSv2

CVE-2012-4092

Published: 26/09/2013 Updated: 22/09/2016
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

The management interface in the Central Software component in Cisco Unified Computing System (UCS) does not properly validate the identity of vCenter consoles, which allows man-in-the-middle malicious users to read or modify an inter-device data stream by spoofing an identity, aka Bug ID CSCtk00683.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco unified computing system -

Vendor Advisories

A vulnerability in the management interface of the Cisco Unified Computing System could allow an unauthenticated, remote attacker to perform a man-in-the-middle attack The vulnerability is due to improper identity validation of vCenter management consoles An attacker could exploit this vulnerability by spoofing their identity and inserting thems ...