Vulnslist

find the latest Cisco vulnerabilities

Cisco Unified Computing System Fabric Interconnect Remote Access Vulnerability

Cisco-SA-20130927-CVS-2012-4136 · Medium · Published · Updated

A vulnerability in the high availability service of Cisco Unified Computing System Fabric Interconnect could allow an unauthenticated, remote attacker to gain access to sensitive information and prevent the cluster service from syncing with its peers. The vulnerability is due to improper binding of the cluster service to the management interface. An attacker could exploit this vulnerability by establishing a Telnet connection to the cluster service from a remote location. A successful exploit could allow the attacker to gain access to sensitive information and modify a field that results in the cluster service unable to sync with its peers. Cisco has confirmed the vulnerability in a security notice and released software updates. To exploit this vulnerability, an attacker must be able to establish a Telnet connection to the cluster service from a remote location. It is likely that this cluster service would reside on a device in an internal trusted network to which an attacker would need access. In addition, the attacker would need to know the name or IP address associated with the targeted device in an attempt to establish a connection. It is recommended to use SSH instead of Telnet, as SSH is the more secured method of establishing remote connections. Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.

Workarounds

Administrators are advised to apply the appropriate updates.

Administrators are advised to allow only trusted users to have network access.

Administrators may consider using IP-based access control lists (ACLs) to allow only trusted systems to access the affected systems.

Administrators are advised to monitor affected systems.

CVEsCVE-2012-4136
Cisco Bug IDsCSCtz72910
CVSS ScoreBase 5.8
Base 5.8 AV:N/AC:M/Au:N/C:P/I:P/A:N/E:F/RL:OF/RC:C
Product Names From Source
Cisco Unified Computing System (Managed)

CSAF Product Statuses

Product Status Source CVE Rows
Cisco Unified Computing System (Managed) known_affected cisco_csaf CVE-2012-4136 1

Related Products

Product CVE Evidence
Cisco Unified Computing System (Managed) CVE-2012-4136 Cisco OpenVuln