CVE-2012-4078
published 2013-09-24CVE-2012-4078: The Baseboard Management Controller (BMC) in Cisco Unified Computing System (UCS) does not properly handle SSH escape sequences, which allows remote…
PriorityP344high8.5CVSS 2.0
AVNACMAuSCCICAC
EPSS
3.54%
88.0th percentile
The Baseboard Management Controller (BMC) in Cisco Unified Computing System (UCS) does not properly handle SSH escape sequences, which allows remote authenticated users to bypass an unspecified authentication step via SSH port forwarding, aka Bug ID CSCtg17656.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
CVSS provenance
nvdv2.08.5HIGHAV:N/AC:M/Au:S/C:C/I:C/A:C
vendor_cisco8.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Unified Computing System Baseboard Management Controller Privilege Escalation Vulnerability
vendor_cisco·2013-09-24·CVSS 8.5
CVE-2012-4078 [HIGH] CWE-264 Cisco Unified Computing System Baseboard Management Controller Privilege Escalation Vulnerability
Cisco Unified Computing System Baseboard Management Controller Privilege Escalation Vulnerability
A
vulnerability in the Baseboard Management Controller (BMC) of Cisco Unified
Computing System could allow an authenticated, remote attacker to access
services with elevated privileges.
The vulnerability is due to
improper filtering of SSH escape sequences. An attacker could exploit
this vulnerability by using SSH port forwarding to bypass additional authentication. A successful exploit
could allow the attacker to access certain services with elevated
privileges.
Cisco has confirmed the vulnerability in a security notice and released software updates.
To exploit this vulnerability, an attacker must be able to authenticate to the targeted device. This access requirement limits the likeliho
GHSA
GHSA-wwrw-xchg-gfw3: The Baseboard Management Controller (BMC) in Cisco Unified Computing System (UCS) does not properly handle SSH escape sequences, which allows remote a
ghsa_unreviewed·2022-05-17
CVE-2012-4078 [HIGH] CWE-287 GHSA-wwrw-xchg-gfw3: The Baseboard Management Controller (BMC) in Cisco Unified Computing System (UCS) does not properly handle SSH escape sequences, which allows remote a
The Baseboard Management Controller (BMC) in Cisco Unified Computing System (UCS) does not properly handle SSH escape sequences, which allows remote authenticated users to bypass an unspecified authentication step via SSH port forwarding, aka Bug ID CSCtg17656.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2012-4078http://www.securitytracker.com/id/1029084https://exchange.xforce.ibmcloud.com/vulnerabilities/87367http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2012-4078http://www.securitytracker.com/id/1029084https://exchange.xforce.ibmcloud.com/vulnerabilities/87367
2013-09-24
Published