CVE-2012-4078 — Improper Authentication in Cisco Unified Computing System
Severity
8.5HIGHNVD
EPSS
0.9%
top 24.01%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 24
Latest updateMay 17
Description
The Baseboard Management Controller (BMC) in Cisco Unified Computing System (UCS) does not properly handle SSH escape sequences, which allows remote authenticated users to bypass an unspecified authentication step via SSH port forwarding, aka Bug ID CSCtg17656.
CVSS vector
AV:N/AC:M/C:C/I:C/A:CExploitability: 6.8 | Impact: 10.0
Affected Packages1 packages
🔴Vulnerability Details
2GHSA▶
GHSA-wwrw-xchg-gfw3: The Baseboard Management Controller (BMC) in Cisco Unified Computing System (UCS) does not properly handle SSH escape sequences, which allows remote a↗2022-05-17
CVEList▶
CVE-2012-4078: The Baseboard Management Controller (BMC) in Cisco Unified Computing System (UCS) does not properly handle SSH escape sequences, which allows remote a↗2013-09-24
📋Vendor Advisories
1Cisco▶
Cisco Unified Computing System Baseboard Management Controller Privilege Escalation Vulnerability↗2013-09-24