The Board Management Controller (BMC) in the Serial over LAN (SoL) subsystem in Cisco Unified Computing System (UCS) relies on a hardcoded private key, which allows man-in-the-middle attackers to obtain sensitive information or modify the data stream by leveraging knowledge of this key, aka Bug ID CSCte90338.
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
http://www.securitytracker.com/id/1029073 | third party advisory vdb entry |
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2012-4074 | vendor advisory |