First published: Fri Sep 20 2013(Updated: )
The Board Management Controller (BMC) in the Serial over LAN (SoL) subsystem in Cisco Unified Computing System (UCS) relies on a hardcoded private key, which allows man-in-the-middle attackers to obtain sensitive information or modify the data stream by leveraging knowledge of this key, aka Bug ID CSCte90338.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified Computing System software |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-4074 is considered a high severity vulnerability due to the potential for man-in-the-middle attacks.
To fix CVE-2012-4074, upgrade the Cisco Unified Computing System software to a version that addresses this vulnerability.
CVE-2012-4074 enables man-in-the-middle attacks which can lead to sensitive information disclosure or data modification.
CVE-2012-4074 affects the Cisco Unified Computing System software.
There is no specific workaround for CVE-2012-4074; updating the software is the recommended mitigation.