CVE-2012-4087
- EPSS 0.51%
- Published 24.09.2013 10:35:51
- Last modified 11.04.2025 00:51:21
A cluster setup script for fabric interconnect devices in Cisco Unified Computing System (UCS) allows remote attackers to execute arbitrary commands via invalid parameters, aka Bug ID CSCtg20793.
CVE-2012-4094
- EPSS 0.84%
- Published 24.09.2013 10:35:51
- Last modified 11.04.2025 00:51:21
Buffer overflow in the Smart Call Home feature in the fabric interconnect in Cisco Unified Computing System (UCS) allows remote attackers to cause a denial of service by reading and forging control messages associated with Smart Call Home reports, ak...
CVE-2012-4082
- EPSS 0.13%
- Published 20.09.2013 18:55:09
- Last modified 11.04.2025 00:51:21
MCTools in the Cisco Management Controller in Cisco Unified Computing System (UCS) allows local users to gain privileges by entering crafted command-line parameters on a Fabric Interconnect device, aka Bug ID CSCtg20749.
CVE-2012-4093
- EPSS 0.12%
- Published 20.09.2013 16:55:07
- Last modified 11.04.2025 00:51:21
The Manager component in Cisco Unified Computing System (UCS) allows local users to cause a denial of service via an invalid Smart Call Home contact address, aka Bug ID CSCtl00186.
- EPSS 0.69%
- Published 20.09.2013 16:55:07
- Last modified 11.04.2025 00:51:21
Multiple buffer overflows in the administrative web interface in Cisco Unified Computing System (UCS) allow remote authenticated users to cause a denial of service (memory corruption and session termination) via long string values for unspecified par...
CVE-2012-4074
- EPSS 0.33%
- Published 20.09.2013 16:55:07
- Last modified 11.04.2025 00:51:21
The Board Management Controller (BMC) in the Serial over LAN (SoL) subsystem in Cisco Unified Computing System (UCS) relies on a hardcoded private key, which allows man-in-the-middle attackers to obtain sensitive information or modify the data stream...
CVE-2012-4073
- EPSS 0.18%
- Published 20.09.2013 16:55:07
- Last modified 11.04.2025 00:51:21
The KVM subsystem in the client in Cisco Unified Computing System (UCS) does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers, and read or modify KVM data, via a crafted certificate, aka Bug ID...
CVE-2012-4072
- EPSS 0.18%
- Published 20.09.2013 16:55:03
- Last modified 11.04.2025 00:51:21
The KVM subsystem in Cisco Unified Computing System (UCS) relies on a hardcoded X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers, and read keyboard and mouse events, by leveraging knowledge of this certificate's privat...
- EPSS 0.44%
- Published 02.08.2013 12:10:40
- Last modified 11.04.2025 00:51:21
The C-Series Rack Server component 1.4 in Cisco Unified Computing System (UCS) does not properly restrict inbound access to ports, which allows remote attackers to cause a denial of service (Integrated Management Controller reboot or hang) via crafte...
CVE-2011-2569
- EPSS 0.06%
- Published 27.10.2011 21:55:00
- Last modified 11.04.2025 00:51:21
Cisco Nexus OS (aka NX-OS) 4.2 and 5.0 and Cisco Unified Computing System with software 1.4 and 2.0 do not properly restrict command-line options, which allows local users to gain privileges via unspecified vectors, aka Bug IDs CSCtf40008, CSCtg18363...