Cisco Unified Computing System Serial over LAN Static Private Key Vulnerability (CSCte90338)

medium Nessus Plugin ID 72458

Synopsis

The remote device is missing a vendor-supplied security patch.

Description

A vulnerability in the Cisco Unified Computing System Serial over LAN (SoL) implementation could allow an unauthenticated, remote attacker to perform a man-in-the-middle (MITM) attack.

The vulnerability occurs because the Board Management Controller (BMC) uses a hard-coded private key. An attacker could exploit this vulnerability by intercepting an SoL connection. Successful exploitation could allow the attacker to view or modify SoL communications.

Solution

Apply the relevant patch referenced in Cisco Bug Id CSCte90338.

See Also

http://www.nessus.org/u?9d78491b

Plugin Details

Severity: Medium

ID: 72458

File Name: cisco-sn-CSCte90338-ucs.nasl

Version: 1.4

Type: remote

Family: CISCO

Published: 2/12/2014

Updated: 11/26/2019

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.2

CVSS v2

Risk Factor: Medium

Base Score: 5.8

Temporal Score: 4.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:N

CVSS Score Source: CVE-2012-4074

Vulnerability Information

CPE: cpe:/h:cisco:unified_computing_system

Required KB Items: www/cisco_ucs_manager

Exploit Ease: No known exploits are available

Patch Publication Date: 9/17/2013

Vulnerability Publication Date: 9/17/2013

Reference Information

CVE: CVE-2012-4074

BID: 62455

CISCO-BUG-ID: CSCte90338