First published: Wed Oct 02 2013(Updated: )
The create certreq command in the fabric-interconnect component in Cisco Unified Computing System (UCS) allows local users to gain privileges by embedding commands in an unspecified parameter, aka Bug ID CSCtq86563.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Unified Computing System software |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-4111 has a medium severity rating due to the potential for local privilege escalation.
To fix CVE-2012-4111, you should update your Cisco Unified Computing System software to the latest patched version.
CVE-2012-4111 could allow local users to execute unauthorized commands and gain elevated privileges on the system.
Local users with access to the Cisco Unified Computing System may be affected by CVE-2012-4111.
CVE-2012-4111 is not remotely exploitable as it requires local access to the affected system.