CVE-2012-4116: Infoleak
The fabric-interconnect component in Cisco Unified Computing System (UCS) does not encrypt KVM media traffic, which allows remote attackers to obtain sensitive information, and consequently complete the authentication process for a server connection, by sniffing the network, aka Bug ID CSCtr72970.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4116?
CVE-2012-4116 has a severity rating of high due to the potential exposure of sensitive information.
How do I fix CVE-2012-4116?
To mitigate CVE-2012-4116, ensure that the Cisco Unified Computing System is updated to the latest version provided by Cisco.
What type of information can be compromised by CVE-2012-4116?
CVE-2012-4116 allows remote attackers to sniff KVM media traffic, potentially exposing credentials and other sensitive information.
Which systems are affected by CVE-2012-4116?
CVE-2012-4116 affects the fabric-interconnect component of Cisco Unified Computing System software.
Is CVE-2012-4116 related to encryption vulnerabilities?
Yes, CVE-2012-4116 is specifically related to the lack of encryption for KVM media traffic in Cisco UCS.