CVE-2012-3063
Description
Cisco Application Control Engine (ACE) before A4(2.3) and A5 before A5(1.1), when multicontext mode is enabled, does not properly share a management IP address among multiple contexts, which allows remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances, and read or modify configuration settings, via a login attempt to a context, aka Bug ID CSCts30631, a different vulnerability than CVE-2012-3058.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| cisco | application_control_engine_software | {"endIncluding":"a4\\(2.0\\)"} | |
| cisco | application_control_engine_software | a1\(7\) | |
| cisco | application_control_engine_software | a1\(7a\) | |
| cisco | application_control_engine_software | a1\(7b\) | |
| cisco | application_control_engine_software | a1\(8\) | |
| cisco | application_control_engine_software | a1\(8a\) | |
| cisco | application_control_engine_software | a3\(1.0\) | |
| cisco | application_control_engine_software | a3\(2.1\) | |
| cisco | application_control_engine_software | a3\(2.2\) | |
| cisco | application_control_engine_software | a3\(2.3\) | |
| cisco | application_control_engine_software | a3\(2.4\) | |
| cisco | application_control_engine_software | a3\(2.5\) | |
| cisco | application_control_engine_software | a3\(2.6\) | |
| cisco | application_control_engine_software | a3\(2.7\) | |
| cisco | application_control_engine_software | a4\(1.0\) | |
| cisco | application_control_engine_software | a4\(1.1\) | |
| cisco | application_control_engine_software | a4\(2.1\) | |
| cisco | application_control_engine_software | a4\(2.2\) | |
| cisco | application_control_engine_software | a5\(1.0\) | |
References
CWEs
CWE-362
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.