The KVM subsystem in the client in Cisco Unified Computing System (UCS) does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers, and read or modify KVM data, via a crafted certificate, aka Bug ID CSCte90332.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Unified_computing_system | Cisco | - (including) | - (including) |