CVE-2012-4109 describes a privilege escalation vulnerability in the Cisco Unified Computing System (UCS) fabric-interconnect component. Specifically, the clear sshkey command allows authenticated local users to embed commands within an unspecified parameter, leading to elevated privileges. This vulnerability has a CVSS score of 6.8, indicating a medium severity risk with local access, low attack complexity, and complete compromise of confidentiality, integrity, and availability. There is no public exploit code available, nor is there evidence of active exploitation, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:h:cisco:unified_computing_system:-:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:S/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.