VulnerabilityModified
CVE-2012-4085
The Intelligent Platform Management Interface (IPMI) implementation in the Blade Management Controller in Cisco Unified Computing System (UCS) allows remote attackers to enumerate valid usernames by observing IPMI interface responses, aka Bug ID…
MEDIUM 5.0EPSS 1.65%
Does this matter?
Lower severity and a low EPSS score (1.65%). Track it; it rarely justifies an emergency change on its own.
Description
The Intelligent Platform Management Interface (IPMI) implementation in the Blade Management Controller in Cisco Unified Computing System (UCS) allows remote attackers to enumerate valid usernames by observing IPMI interface responses, aka Bug ID CSCtg20761.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.65% probability · 75th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- cisco/unified computing system
- Source
- psirt@cisco.com
References
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2012-4085Vendor Advisory
- http://www.securitytracker.com/id/1029081Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/87372
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2012-4085Vendor Advisory
- http://www.securitytracker.com/id/1029081Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/87372
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.