CVE-2012-4081
published 2013-09-20CVE-2012-4081: MCServer in the Cisco Management Controller in Cisco Unified Computing System (UCS) allows local users to cause a denial of service (application crash) via…
PriorityP414medium4.6CVSS 2.0
AVLACLAuSCNINAC
EPSS
0.30%
22.5th percentile
MCServer in the Cisco Management Controller in Cisco Unified Computing System (UCS) allows local users to cause a denial of service (application crash) via invalid MCTools parameters, aka Bug ID CSCtg20734.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
| cisco | unified_computing_system | — | — |
CVSS provenance
nvdv2.04.6MEDIUMAV:L/AC:L/Au:S/C:N/I:N/A:C
vendor_redhat5.5MEDIUM
vendor_cisco4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p4jw-hpfq-3fc6: MCServer in the Cisco Management Controller in Cisco Unified Computing System (UCS) allows local users to cause a denial of service (application crash
ghsa_unreviewed·2022-05-17
CVE-2012-4081 [MEDIUM] CWE-119 GHSA-p4jw-hpfq-3fc6: MCServer in the Cisco Management Controller in Cisco Unified Computing System (UCS) allows local users to cause a denial of service (application crash
MCServer in the Cisco Management Controller in Cisco Unified Computing System (UCS) allows local users to cause a denial of service (application crash) via invalid MCTools parameters, aka Bug ID CSCtg20734.
Cisco
Cisco Unified Computing System Cisco Management Controller Denial of Service Vulnerability
vendor_cisco·2013-09-18·CVSS 4.6
CVE-2012-4081 [MEDIUM] CWE-20 Cisco Unified Computing System Cisco Management Controller Denial of Service Vulnerability
Cisco Unified Computing System Cisco Management Controller Denial of Service Vulnerability
A vulnerability in the Cisco Management Controller of the Cisco Unified Computing System could allow an authenticated, local attacker to trigger a denial of service (DoS) condition.
The vulnerability is due to improper parameter input validation. An attacker could exploit this vulnerability by providing invalid parameters to the MCTools application, causing the MCServer application to terminate. A successful exploit could allow the attacker to trigger a DoS condition.
Cisco has confirmed the vulnerability in a security notice and released software updates.
To exploit this vulnerability, an attacker must be able to authenticate and have local access to the targeted device. These access requiremen
Red Hat
kernel: crypto: ghash: null pointer deref if no key is set
vendor_redhat·2011-10-20·CVSS 5.5
CVE-2011-4081 [MEDIUM] CWE-476 kernel: crypto: ghash: null pointer deref if no key is set
kernel: crypto: ghash: null pointer deref if no key is set
crypto/ghash-generic.c in the Linux kernel before 3.1 allows local users to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact by triggering a failed or missing ghash_setkey function call, followed by a (1) ghash_update function call or (2) ghash_final function call, as demonstrated by a write operation on an AF_ALG socket.
Statement: This issue did not affect the Linux kernels as shipped with Red Hat Enterprise Linux 4, and 5 as they did not include support for the GHASH message digest algorithm. This has been addressed in Red Hat Enterprise Linux 6, and MRG via https://rhn.redhat.com/errata/RHSA-2012-0350.html, and https://rhn.redhat.com/errata/RHSA-2012-0010.html.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2013-09-20
Published