CVE-2012-4116

Description

The fabric-interconnect component in Cisco Unified Computing System (UCS) does not encrypt KVM media traffic, which allows remote attackers to obtain sensitive information, and consequently complete the authentication process for a server connection, by sniffing the network, aka Bug ID CSCtr72970.

Risk Information

Base Score
5.8
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
EPSS Score
Exploitation Probability
0.265

Associated Vulnerability

VulnerabilityOS Platform
Cisco Unified Computing System Fabric Interconnect Information Disclosure Vulnerability For Cisco Unified Computing SystemNCM
Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-4116)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-1706036Security Update for Cisco Unified Computing System 3.2(1d)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234