First published: Tue Sep 24 2013(Updated: )
The Baseboard Management Controller (BMC) in Cisco Unified Computing System (UCS) does not properly handle SSH escape sequences, which allows remote authenticated users to bypass an unspecified authentication step via SSH port forwarding, aka Bug ID CSCtg17656.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified Computing System software | =1.0\(2k\) | |
Cisco Unified Computing System software | =1.0_base | |
Cisco Unified Computing System software | =1.1\(1m\) | |
Cisco Unified Computing System software | =1.1_base |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-4078 is classified as a medium severity vulnerability.
To mitigate CVE-2012-4078, update your Cisco Unified Computing System software to the latest version that addresses this vulnerability.
CVE-2012-4078 allows remote authenticated users to bypass an unspecified authentication step via SSH port forwarding.
CVE-2012-4078 affects Cisco Unified Computing System versions 1.0(2k), 1.0_base, 1.1(1m), and 1.1_base.
CVE-2012-4078 is a remote vulnerability that requires authenticated access to exploit.