VULNERABILITY INTELLIGENCE
CVE-2012-4073
CVSS score5.8 MEDIUM
EPSS probability0.60%
CISA KEVNot currently listed
Published2013-09-20
Last modified2026-06-16
CVSS vectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Description
The KVM subsystem in the client in Cisco Unified Computing System (UCS) does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers, and read or modify KVM data, via a crafted certificate, aka Bug ID CSCte90332.
Primary references
- psirt@cisco.com — Vendor Advisory
- psirt@cisco.com — Third Party Advisory, VDB Entry
- af854a3a-2127-422b-91ae-364da2661108 — Vendor Advisory
- af854a3a-2127-422b-91ae-364da2661108 — Third Party Advisory, VDB Entry