CVE-2012-4092: Input Validation
The management interface in the Central Software component in Cisco Unified Computing System (UCS) does not properly validate the identity of vCenter consoles, which allows man-in-the-middle attackers to read or modify an inter-device data stream by spoofing an identity, aka Bug ID CSCtk00683.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4092?
CVE-2012-4092 is rated as a high severity vulnerability due to its potential for man-in-the-middle attacks leading to unauthorized access.
How do I fix CVE-2012-4092?
To fix CVE-2012-4092, upgrade to the latest version of Cisco Unified Computing System software that addresses the identity validation issue.
Who is affected by CVE-2012-4092?
CVE-2012-4092 affects users of the Cisco Unified Computing System software using the management interface.
What is the impact of CVE-2012-4092?
The impact of CVE-2012-4092 allows attackers to read or modify inter-device data streams through identity spoofing.
Is there a workaround for CVE-2012-4092?
Currently, there are no known workarounds for CVE-2012-4092, and users are advised to apply the security patch.