ID

VAR-201310-0007


CVE

CVE-2012-4084


TITLE

Cisco Unified Computing System Vulnerable to cross-site request forgery

Trust: 0.8

sources: JVNDB: JVNDB-2013-004518

DESCRIPTION

Cross-site request forgery (CSRF) vulnerability in the web-management interface in the fabric interconnect (FI) component in Cisco Unified Computing System (UCS) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCtg20755. Vendors have confirmed this vulnerability Bug ID CSCtg20755 It is released as.A third party may be able to hijack the authentication of any user. The Cisco Unified Computing System simplifies IT management and increases flexibility by consolidating unified computing, networking, storage access, and virtualization into one system. An attacker can construct a malicious URI, entice the logged in user to resolve, and perform arbitrary operations in the target user context. Other attacks are also possible. This issue is being tracked by Cisco bug ID CSCtg20755. The system integrates network, computing and virtualization resources into one platform by extensively adopting virtualization technology

Trust: 2.52

sources: NVD: CVE-2012-4084 // JVNDB: JVNDB-2013-004518 // CNVD: CNVD-2013-13628 // BID: 62851 // VULHUB: VHN-57365

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2013-13628

AFFECTED PRODUCTS

vendor:ciscomodel:unified computing systemscope:eqversion: -

Trust: 1.6

vendor:ciscomodel:unified computing systemscope: - version: -

Trust: 1.4

sources: CNVD: CNVD-2013-13628 // JVNDB: JVNDB-2013-004518 // CNNVD: CNNVD-201310-014 // NVD: CVE-2012-4084

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2012-4084
value: MEDIUM

Trust: 1.0

NVD: CVE-2012-4084
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2013-13628
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201310-014
value: MEDIUM

Trust: 0.6

VULHUB: VHN-57365
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2012-4084
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2013-13628
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-57365
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: CNVD: CNVD-2013-13628 // VULHUB: VHN-57365 // JVNDB: JVNDB-2013-004518 // CNNVD: CNNVD-201310-014 // NVD: CVE-2012-4084

PROBLEMTYPE DATA

problemtype:CWE-352

Trust: 1.9

sources: VULHUB: VHN-57365 // JVNDB: JVNDB-2013-004518 // NVD: CVE-2012-4084

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201310-014

TYPE

cross-site request forgery

Trust: 0.6

sources: CNNVD: CNNVD-201310-014

CONFIGURATIONS

sources: JVNDB: JVNDB-2013-004518

PATCH

title:Cisco Unified Computing System Fabric Interconnect Cross-Site Request Forgery Vulnerabilityurl:http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2012-4084

Trust: 0.8

title:Patch for Cisco Unified Computing System Cross-Site Request Forgery Vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/40060

Trust: 0.6

sources: CNVD: CNVD-2013-13628 // JVNDB: JVNDB-2013-004518

EXTERNAL IDS

db:NVDid:CVE-2012-4084

Trust: 3.4

db:BIDid:62851

Trust: 2.0

db:SECUNIAid:55203

Trust: 1.1

db:OSVDBid:98125

Trust: 1.1

db:JVNDBid:JVNDB-2013-004518

Trust: 0.8

db:CNNVDid:CNNVD-201310-014

Trust: 0.7

db:CNVDid:CNVD-2013-13628

Trust: 0.6

db:CISCOid:20131004 CISCO UNIFIED COMPUTING SYSTEM FABRIC INTERCONNECT CROSS-SITE REQUEST FORGERY VULNERABILITY

Trust: 0.6

db:VULHUBid:VHN-57365

Trust: 0.1

sources: CNVD: CNVD-2013-13628 // VULHUB: VHN-57365 // BID: 62851 // JVNDB: JVNDB-2013-004518 // CNNVD: CNNVD-201310-014 // NVD: CVE-2012-4084

REFERENCES

url:http://tools.cisco.com/security/center/content/ciscosecuritynotice/cve-2012-4084

Trust: 1.7

url:http://www.securityfocus.com/bid/62851

Trust: 1.1

url:http://osvdb.org/98125

Trust: 1.1

url:http://secunia.com/advisories/55203

Trust: 1.1

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/87679

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2012-4084

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2012-4084

Trust: 0.8

url:http://tools.cisco.com/security/center/content/ciscosecuritynotice/cve-2012-4084http

Trust: 0.6

url:http://www.cisco.com/

Trust: 0.3

sources: CNVD: CNVD-2013-13628 // VULHUB: VHN-57365 // BID: 62851 // JVNDB: JVNDB-2013-004518 // CNNVD: CNNVD-201310-014 // NVD: CVE-2012-4084

CREDITS

Cisco

Trust: 0.3

sources: BID: 62851

SOURCES

db:CNVDid:CNVD-2013-13628
db:VULHUBid:VHN-57365
db:BIDid:62851
db:JVNDBid:JVNDB-2013-004518
db:CNNVDid:CNNVD-201310-014
db:NVDid:CVE-2012-4084

LAST UPDATE DATE

2024-08-14T13:35:33.261000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2013-13628date:2013-10-12T00:00:00
db:VULHUBid:VHN-57365date:2017-08-29T00:00:00
db:BIDid:62851date:2013-10-04T00:00:00
db:JVNDBid:JVNDB-2013-004518date:2013-10-08T00:00:00
db:CNNVDid:CNNVD-201310-014date:2013-10-08T00:00:00
db:NVDid:CVE-2012-4084date:2017-08-29T01:32:09.603

SOURCES RELEASE DATE

db:CNVDid:CNVD-2013-13628date:2013-10-11T00:00:00
db:VULHUBid:VHN-57365date:2013-10-05T00:00:00
db:BIDid:62851date:2013-10-04T00:00:00
db:JVNDBid:JVNDB-2013-004518date:2013-10-08T00:00:00
db:CNNVDid:CNNVD-201310-014date:2013-10-08T00:00:00
db:NVDid:CVE-2012-4084date:2013-10-05T10:55:03.290