CVE-2012-4074: Medium severity cisco unified computing system software vulnerability
The Board Management Controller (BMC) in the Serial over LAN (SoL) subsystem in Cisco Unified Computing System (UCS) relies on a hardcoded private key, which allows man-in-the-middle attackers to obtain sensitive information or modify the data stream by leveraging knowledge of this key, aka Bug ID CSCte90338.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4074?
CVE-2012-4074 is considered a high severity vulnerability due to the potential for man-in-the-middle attacks.
How do I fix CVE-2012-4074?
To fix CVE-2012-4074, upgrade the Cisco Unified Computing System software to a version that addresses this vulnerability.
What type of attacks does CVE-2012-4074 enable?
CVE-2012-4074 enables man-in-the-middle attacks which can lead to sensitive information disclosure or data modification.
Which products are affected by CVE-2012-4074?
CVE-2012-4074 affects the Cisco Unified Computing System software.
Is there a workaround for CVE-2012-4074?
There is no specific workaround for CVE-2012-4074; updating the software is the recommended mitigation.